« Back to list

Microsoft

Microsoft Power Automate FOR Desktop: vulnerabilities and CVEs

Microsoft Power Automate FOR Desktop has 5 published vulnerabilities, 2 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs5
Last 12 months2
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-77897High (7)0.28%—Sep 8, 2026
Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally.
CVE-2026-40374Medium (6.5)1.00%—May 12, 2026
Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network.
CVE-2025-47966Critical (9.8)1.2%—Jun 5, 2025
Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-29817Medium (5.7)0.90%—Apr 15, 2025
Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.
CVE-2025-21187High (7.8)0.75%—Jan 14, 2025
Microsoft Power Automate Remote Code Execution Vulnerability

Other products by Microsoft