Published January 24, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.
Published January 23, 2026
Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network.
Published January 23, 2026
Improper limitation of a pathname to a restricted directory (‘path traversal’) in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
Published January 23, 2026
Azure Entra ID Elevation of Privilege Vulnerability
Published January 23, 2026
Exposure of sensitive information to an unauthorized actor in Azure Data Explorer allows an unauthorized attacker to disclose information over a network.
Published January 23, 2026
Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network.
Published January 23, 2026
Improper neutralization of input during web page generation (‘cross-site scripting’) in Microsoft Account allows an unauthorized attacker to perform spoofing over a network.
Published January 23, 2026
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
Published January 23, 2026
Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector
Published January 23, 2026
Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network.