Vulnerabilities

Summary — last 7 days

New vulnerabilities2,702▼ 361 vs. last week
Critical / high1,278▼ 199 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)216▼ 113 vs. last week
–

27 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedHigh (8.6)1.0%—Microsoft Azure Stack HCI8/20/20268/25/2026
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
AnalyzedCritical (9.8)0.97%—Microsoft Azure Stack Edge6/9/20267/23/2026
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.
AnalyzedHigh (8.4)0.83%—Microsoft Azure Stack Edge6/9/20267/23/2026
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.
AnalyzedHigh (7.7)1.0%—Microsoft Azure Stack HCI5/22/20267/23/2026
Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.
AnalyzedHigh (7.5)1.3%—Microsoft Azure Stack HUB8/12/20256/17/2026
Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network.
AnalyzedMedium (5.5)0.49%—Microsoft Azure APP Service ON Azure Stack8/12/20256/17/2026
Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally.
AnalyzedHigh (7.8)0.61%—Microsoft Azure Stack HCI 22h2Microsoft Azure Stack HCI 23h24/8/20256/17/2026
Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally.
AnalyzedHigh (8.8)0.37%—Microsoft Azure Stack HCI11/15/20246/17/2026
Azure Stack HCI Elevation of Privilege Vulnerability
AnalyzedHigh (8.8)0.44%—Microsoft Azure Stack HCI10/8/20246/17/2026
Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability
AnalyzedCritical (9)1.0%—Microsoft Azure Stack HUB9/10/20248/10/2026
Azure Stack Hub Elevation of Privilege Vulnerability
AnalyzedCritical (9)0.92%—Microsoft Azure Stack HUB9/10/20248/10/2026
Azure Stack Hub Elevation of Privilege Vulnerability
AnalyzedHigh (7)0.65%—Microsoft Azure Stack HUB8/13/20246/17/2026
Azure Stack Hub Elevation of Privilege Vulnerability
AnalyzedCritical (9.3)1.2%—Microsoft Azure Stack HUB8/13/20246/17/2026
Azure Stack Hub Spoofing Vulnerability
ModifiedMedium (6.5)1.3%—Microsoft Azure Stack HUB2/13/20248/10/2026
Azure Stack Hub Spoofing Vulnerability
ModifiedHigh (8.7)0.35%—Microsoft Azure APP Service ON Azure Stack2/14/20238/19/2026
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
ModifiedHigh (7.2)1.5%—Microsoft Azure Data BOX GatewayMicrosoft Azure Stack Edge2/14/20238/19/2026
Azure Data Box Gateway Remote Code Execution Vulnerability
ModifiedCritical (10)3.0%—Microsoft Azure Arc-enabled KubernetesMicrosoft Azure Stack Edge10/11/20226/17/2026
Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over the Kubernetes cluster. Additionally, because Azure Stack Edge…
ModifiedHigh (7.8)0.92%—Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure DiagnosticsMicrosoft Azure Security Center+66/15/20226/17/2026
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
ModifiedCritical (9.9)0.93%—Dell EMC Integrated System FOR Microsoft Azure Stack HUB Firmware2/9/20226/17/2026
All Dell EMC Integrated System for Microsoft Azure Stack Hub versions contain a privilege escalation vulnerability. A remote malicious user with standard level JEA credentials may potentially exploit this vulnerability to elevate privileges and take over the system.
AnalyzedHigh (7.8)2.9%⚠ Active exploitationMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+79/15/20218/10/2026
Open Management Infrastructure Elevation of Privilege Vulnerability
AnalyzedHigh (7.8)11%⚠ Active exploitation💥 ExploitMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+79/15/20218/10/2026
Open Management Infrastructure Elevation of Privilege Vulnerability
AnalyzedCritical (9.8)100%⚠ Active exploitation💥 ExploitMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+69/15/20218/10/2026
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
AnalyzedHigh (7.8)2.7%⚠ Active exploitationMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+69/15/20218/10/2026
Open Management Infrastructure Elevation of Privilege Vulnerability
ModifiedCritical (9.8)2.4%—Dell EMC Integrated System FOR Microsoft Azure Stack HUB Firmware5/6/20216/17/2026
Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could potentially exploit this to log in to the system to gain root privileges.
ModifiedHigh (7.5)75%—Microsoft Azure Stack11/12/20196/17/2026
A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerability'.
Orbitaley — Vulnerabilities