Published January 23, 2026
Improper neutralization of input during web page generation (‘cross-site scripting’) in Microsoft Account allows an unauthorized attacker to perform spoofing over a network.
Published January 23, 2026
Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network.
Published January 23, 2026
Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view sensitive information through network attack vector
Published January 23, 2026
Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized attacker to disclose information over a network.
Published January 21, 2026
Updated the build numbers. This is an informational update only.
Published January 21, 2026
Updated the build numbers. This is an informational update only.
Published January 21, 2026
Updated the build numbers. This is an informational update only.
Published January 21, 2026
Updated the build numbers. This is an informational update only.
Published January 21, 2026
Updated FAQ information. This is an informational change only.
Published January 16, 2026
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.