Known Vulnerabilities for Microsoft 365 by Microsoft
Listed below are 10 of the newest known vulnerabilities associated with "Microsoft 365" by "Microsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-50512 json | Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to eleva... | Not Provided | 2026-06-09 | 2026-06-09 |
| CVE-2026-50511 json | Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to eleva... | Not Provided | 2026-06-09 | 2026-06-09 |
| CVE-2026-49161 json | Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally. | Not Provided | 2026-06-09 | 2026-06-09 |
| CVE-2026-49139 json | Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler th... | Not Provided | 2026-06-01 | 2026-06-01 |
| CVE-2026-48579 json | Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network. | Not Provided | 2026-06-04 | 2026-06-04 |
| CVE-2026-48562 json | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an... | Not Provided | 2026-06-09 | 2026-06-09 |
| CVE-2026-48560 json | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an... | Not Provided | 2026-06-09 | 2026-06-09 |
| CVE-2026-47655 json | Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose infor... | Not Provided | 2026-06-04 | 2026-06-04 |
| CVE-2026-47644 json | Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft... | Not Provided | 2026-06-04 | 2026-06-06 |
| CVE-2026-47641 json | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an... | Not Provided | 2026-06-09 | 2026-06-10 |