« Volver al listado

Microsoft

Microsoft Entra ID: vulnerabilidades y CVE

Microsoft Entra ID tiene 15 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 10 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE15
Últimos 12 meses13
Críticas10
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-83941Alta (8.8)0.78%—8 sept 2026
Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.
CVE-2026-62916Crítica (9.8)0.86%—3 sept 2026
Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-69851Crítica (9.9)0.78%—20 ago 2026
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
CVE-2026-69836Crítica (10)1.5%—20 ago 2026
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
CVE-2026-62869Alta (8.8)0.44%—11 ago 2026
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
CVE-2026-42901Crítica (10)0.46%—22 may 2026
Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-33843Crítica (9.8)0.86%—22 may 2026
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-42177Media (5.3)0.31%—12 may 2026
linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter is Platform.SSO_URL +…
CVE-2026-40379Alta (7.5)0.95%—12 may 2026
Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-35431Crítica (10)0.90%—23 abr 2026
Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-24305Crítica (9.8)0.55%—22 ene 2026
Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-59246Crítica (9.8)7.7%—9 oct 2025
Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-59218Crítica (9.6)0.66%—9 oct 2025
Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-55241Crítica (9.8)1.6%—4 sept 2025
Azure Entra ID Elevation of Privilege Vulnerability
CVE-2024-43477Alta (7.5)1.0%—23 ago 2024
Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant.

Otros productos de Microsoft