Microsoft
Microsoft Entra ID: vulnerabilidades y CVE
Microsoft Entra ID tiene 15 vulnerabilidades publicadas, 13 de ellas en los últimos 12 meses. 10 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses13
Críticas10
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-83941 | Alta (8.8) | 0.78% | — | 8 sept 2026 | Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-62916 | Crítica (9.8) | 0.86% | — | 3 sept 2026 | Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-69851 | Crítica (9.9) | 0.78% | — | 20 ago 2026 | Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-69836 | Crítica (10) | 1.5% | — | 20 ago 2026 | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. |
| CVE-2026-62869 | Alta (8.8) | 0.44% | — | 11 ago 2026 | Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network. |
| CVE-2026-42901 | Crítica (10) | 0.46% | — | 22 may 2026 | Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-33843 | Crítica (9.8) | 0.86% | — | 22 may 2026 | Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-42177 | Media (5.3) | 0.31% | — | 12 may 2026 | linux-entra-sso is a browser plugin for Linux to SSO on Microsoft Entra ID. Prior to 1.8.1, platform/chrome/js/platform-chrome.js:69-88 registers a single declarativeNetRequest rule whose urlFilter is Platform.SSO_URL +… |
| CVE-2026-40379 | Alta (7.5) | 0.95% | — | 12 may 2026 | Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-35431 | Crítica (10) | 0.90% | — | 23 abr 2026 | Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-24305 | Crítica (9.8) | 0.55% | — | 22 ene 2026 | Azure Entra ID Elevation of Privilege Vulnerability |
| CVE-2025-59246 | Crítica (9.8) | 7.7% | — | 9 oct 2025 | Azure Entra ID Elevation of Privilege Vulnerability |
| CVE-2025-59218 | Crítica (9.6) | 0.66% | — | 9 oct 2025 | Azure Entra ID Elevation of Privilege Vulnerability |
| CVE-2025-55241 | Crítica (9.8) | 1.6% | — | 4 sept 2025 | Azure Entra ID Elevation of Privilege Vulnerability |
| CVE-2024-43477 | Alta (7.5) | 1.0% | — | 23 ago 2024 | Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant. |