Azure Active Directory
by Microsoft
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-45480 | Cri | 0.65 | 10.0 | 0.01 | Jun 19, 2026 | Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2026-50481 | Cri | 0.64 | 9.9 | — | Aug 7, 2026 | Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2021-42306 | Hig | 0.53 | 8.1 | 0.03 | Nov 24, 2021 | An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal (which is not recommended). This vulnerability allows a… | ||
| CVE-2024-21381 | Med | 0.44 | 6.8 | 0.00 | Feb 13, 2024 | Microsoft Azure Active Directory B2C Spoofing Vulnerability | ||
| CVE-2026-50653 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-50652 | Hig | 0.00 | 7.5 | 0.01 | Jul 14, 2026 | Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network. |
- risk 0.65cvss 10.0epss 0.01
Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
- risk 0.64cvss 9.9epss —
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
- risk 0.53cvss 8.1epss 0.03
An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal (which is not recommended). This vulnerability allows a…
- risk 0.44cvss 6.8epss 0.00
Microsoft Azure Active Directory B2C Spoofing Vulnerability
- risk 0.00cvss 7.5epss 0.01
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
- risk 0.00cvss 7.5epss 0.01
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.