CVE-2026-50219 libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,
CVE-2026-11332 Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution
CVE-2026-48567 Azure HorizonDB Elevation of Privilege Vulnerability
Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. Continue reading CVE-2026-48567 Azure HorizonDB Elevation of Privilege Vulnerability
CVE-2026-45497 Microsoft M365 Copilot Remote Code Execution Vulnerability
Improper neutralization of special elements used in a command (‘command injection’) in Microsoft Copilot allows an authorized attacker to execute code over a network. Continue reading CVE-2026-45497 Microsoft M365 Copilot Remote Code Execution Vulnerability
CVE-2026-47644 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
Improper neutralization of special elements in output used by a downstream component (‘injection’) in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. Continue reading CVE-2026-47644 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
CVE-2026-47644 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
Improper neutralization of special elements in output used by a downstream component (‘injection’) in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network. Continue reading CVE-2026-47644 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
CVE-2026-47655 Microsoft Graph Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. Continue reading CVE-2026-47655 Microsoft Graph Information Disclosure Vulnerability
