Vulnerabilities
Summary — last 7 days
New vulnerabilities2,702▼ 361 vs. last week
Critical / high1,278▼ 199 vs. last week
New active exploitation (KEV)3▼ 5 vs. last week
Unscored (no CVSS)216▼ 113 vs. last week
27 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | High (8.6) | 1.0% | — | Microsoft Azure Stack HCI | 8/20/2026 | 8/25/2026 | Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network. | |
| Analyzed | Critical (9.8) | 0.97% | — | Microsoft Azure Stack Edge | 6/9/2026 | 7/23/2026 | External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network. | |
| Analyzed | High (8.4) | 0.83% | — | Microsoft Azure Stack Edge | 6/9/2026 | 7/23/2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network. | |
| Analyzed | High (7.7) | 1.0% | — | Microsoft Azure Stack HCI | 5/22/2026 | 7/23/2026 | Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network. | |
| Analyzed | High (7.5) | 1.3% | — | Microsoft Azure Stack HUB | 8/12/2025 | 6/17/2026 | Improper authentication in Azure Stack allows an unauthorized attacker to disclose information over a network. | |
| Analyzed | Medium (5.5) | 0.49% | — | Microsoft Azure APP Service ON Azure Stack | 8/12/2025 | 6/17/2026 | Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally. | |
| Analyzed | High (7.8) | 0.61% | — | Microsoft Azure Stack HCI 22h2Microsoft Azure Stack HCI 23h2 | 4/8/2025 | 6/17/2026 | Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally. | |
| Analyzed | High (8.8) | 0.37% | — | Microsoft Azure Stack HCI | 11/15/2024 | 6/17/2026 | Azure Stack HCI Elevation of Privilege Vulnerability | |
| Analyzed | High (8.8) | 0.44% | — | Microsoft Azure Stack HCI | 10/8/2024 | 6/17/2026 | Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability | |
| Analyzed | Critical (9) | 1.0% | — | Microsoft Azure Stack HUB | 9/10/2024 | 8/10/2026 | Azure Stack Hub Elevation of Privilege Vulnerability | |
| Analyzed | Critical (9) | 0.92% | — | Microsoft Azure Stack HUB | 9/10/2024 | 8/10/2026 | Azure Stack Hub Elevation of Privilege Vulnerability | |
| Analyzed | High (7) | 0.65% | — | Microsoft Azure Stack HUB | 8/13/2024 | 6/17/2026 | Azure Stack Hub Elevation of Privilege Vulnerability | |
| Analyzed | Critical (9.3) | 1.2% | — | Microsoft Azure Stack HUB | 8/13/2024 | 6/17/2026 | Azure Stack Hub Spoofing Vulnerability | |
| Modified | Medium (6.5) | 1.3% | — | Microsoft Azure Stack HUB | 2/13/2024 | 8/10/2026 | Azure Stack Hub Spoofing Vulnerability | |
| Modified | High (8.7) | 0.35% | — | Microsoft Azure APP Service ON Azure Stack | 2/14/2023 | 8/19/2026 | Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability | |
| Modified | High (7.2) | 1.5% | — | Microsoft Azure Data BOX GatewayMicrosoft Azure Stack Edge | 2/14/2023 | 8/19/2026 | Azure Data Box Gateway Remote Code Execution Vulnerability | |
| Modified | Critical (10) | 3.0% | — | Microsoft Azure Arc-enabled KubernetesMicrosoft Azure Stack Edge | 10/11/2022 | 6/17/2026 | Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over the Kubernetes cluster. Additionally, because Azure Stack Edge… | |
| Modified | High (7.8) | 0.92% | — | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure DiagnosticsMicrosoft Azure Security Center+6 | 6/15/2022 | 6/17/2026 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | |
| Modified | Critical (9.9) | 0.93% | — | Dell EMC Integrated System FOR Microsoft Azure Stack HUB Firmware | 2/9/2022 | 6/17/2026 | All Dell EMC Integrated System for Microsoft Azure Stack Hub versions contain a privilege escalation vulnerability. A remote malicious user with standard level JEA credentials may potentially exploit this vulnerability to elevate privileges and take over the system. | |
| Analyzed | High (7.8) | 2.9% | ⚠ Active exploitation | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+7 | 9/15/2021 | 8/10/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Analyzed | High (7.8) | 11% | ⚠ Active exploitation💥 Exploit | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+7 | 9/15/2021 | 8/10/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Analyzed | Critical (9.8) | 100% | ⚠ Active exploitation💥 Exploit | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+6 | 9/15/2021 | 8/10/2026 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | |
| Analyzed | High (7.8) | 2.7% | ⚠ Active exploitation | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+6 | 9/15/2021 | 8/10/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Modified | Critical (9.8) | 2.4% | — | Dell EMC Integrated System FOR Microsoft Azure Stack HUB Firmware | 5/6/2021 | 6/17/2026 | Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could potentially exploit this to log in to the system to gain root privileges. | |
| Modified | High (7.5) | 75% | — | Microsoft Azure Stack | 11/12/2019 | 6/17/2026 | A spoofing vulnerability exists when Azure Stack fails to validate certain requests, aka 'Azure Stack Spoofing Vulnerability'. |