Known Vulnerabilities for Microsoft Entra by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "Microsoft Entra" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-104047 json | A flaw was found in SSSD. When configured to use Microsoft Entra ID, search inputs are not properly sanitized before being in... | Not Provided | 2026-10-06 | 2026-10-06 |
| CVE-2026-104040 json | A flaw was found in SSSD. When configured with the Entra ID identity provider, input lookup names containing single quotes ar... | Not Provided | 2026-10-06 | 2026-10-06 |
| CVE-2026-84672 json | Jenkins Microsoft Entra ID (previously Azure AD) Plugin 710.v0b_ff8e9cc2d2 and earlier grants Entra group permissions using b... | Not Provided | 2026-09-02 | 2026-09-02 |
| CVE-2026-73298 json | The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven ... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-69836 json | Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. | Not Provided | 2026-08-20 | 2026-08-24 |
| CVE-2026-65673 json | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows a... | Not Provided | 2026-08-11 | 2026-08-16 |
| CVE-2026-62916 json | Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate pri... | Not Provided | 2026-09-03 | 2026-09-05 |
| CVE-2026-59115 json | '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a n... | Not Provided | 2026-08-07 | 2026-08-07 |
| CVE-2026-54733 json | The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moo... | Not Provided | 2026-07-16 | 2026-07-16 |
| CVE-2024-21401 json | Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability | Not Provided | 2024-02-13 | 2026-08-10 |