Microsoft
Microsoft Power Automate FOR Desktop: vulnerabilities and CVEs
Microsoft Power Automate FOR Desktop has 5 published vulnerabilities, 2 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs5
Last 12 months2
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77897 | High (7) | 0.28% | — | Sep 8, 2026 | Relative path traversal in Power Automate allows an authorized attacker to elevate privileges locally. |
| CVE-2026-40374 | Medium (6.5) | 1.00% | — | May 12, 2026 | Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network. |
| CVE-2025-47966 | Critical (9.8) | 1.2% | — | Jun 5, 2025 | Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-29817 | Medium (5.7) | 0.90% | — | Apr 15, 2025 | Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network. |
| CVE-2025-21187 | High (7.8) | 0.75% | — | Jan 14, 2025 | Microsoft Power Automate Remote Code Execution Vulnerability |