Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Thomas Knudson

#13880of 53,632
19.4Total CVSS
Vulnerabilities · 2
Critical
2
PT-2026-42849
10
2026-05-21
Microsoft · Entra Id · CVE-2026-42901
**Name of the Vulnerable Software and Affected Versions** Microsoft Entra ID (affected versions not specified) **Description** An origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-40208
9.4
2026-05-07
Microsoft · Azure Entra Id · CVE-2026-40379
**Name of the Vulnerable Software and Affected Versions** Azure Entra ID (affected versions not specified) Microsoft Enterprise Security Token Service (affected versions not specified) **Description** Exposure of sensitive information in Azure Entra ID allows an unauthorized actor to perform spoofing over a network. Additionally, errors in information processing within the Microsoft Enterprise Security Token Service, a service used for authentication and token management, could allow a remote attacker to gain unauthorized access to protected information. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.