« Volver al listado

Microsoft

Microsoft Entra ID: vulnerabilidades y CVE

Microsoft Entra ID tiene 15 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 10 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE15
Últimos 12 meses13
Críticas10
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-83941Alta (8.8)0.78%—8 sept 2026
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.
CVE-2026-62916Crítica (9.8)0.86%—3 sept 2026
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69851Crítica (9.9)0.78%—20 ago 2026
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
CVE-2026-69836Crítica (10)1.5%—20 ago 2026
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
CVE-2026-62869Alta (8.8)0.44%—11 ago 2026
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
CVE-2026-42901Crítica (10)0.46%—22 may 2026
Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-33843Crítica (9.8)0.86%—22 may 2026
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-42177Media (5.3)0.31%—12 may 2026
linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter is Platform.SSO_URL +…
CVE-2026-40379Alta (7.5)0.95%—12 may 2026
Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-35431Crítica (10)0.90%—23 abr 2026
Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-24305Crítica (9.8)0.55%—22 ene 2026
Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-59246Crítica (9.8)7.7%—9 oct 2025
Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-59218Crítica (9.6)0.66%—9 oct 2025
Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-55241Crítica (9.8)1.6%—4 sept 2025
Azure Entra ID Elevation of Privilege Vulnerability
CVE-2024-43477Alta (7.5)1.0%—23 ago 2024
Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application9
  2. T1078 Valid Accounts5
  3. T1068 Exploitation for Privilege Escalation3
  4. T1210 Exploitation of Remote Services3
  5. T1005 Data from Local System1
  6. T1059 Command and Scripting Interpreter1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Microsoft