Skip to content
COOEY
SEARCH
“Microsoft”

4 products · 1 vendor · 1 entity · 501 events.

FEDRAMP PRODUCTS open in catalog →
PRODUCTPROVIDERSTATUSIMPACT
Azure Commercial CloudMicrosoftAuthorizedHigh
Azure Government (includes Dynamics 365)MicrosoftAuthorizedHigh
Microsoft Office 365 GCC HighMicrosoftIn ProcessHigh
Office 365 Multi-Tenant & Supporting ServicesMicrosoftAuthorizedModerate
EVENTS
2026-07-09 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-190-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities...
2026-08-25 CISA advisory
<h2><strong>Advisory at a Glance</strong></h2> <table> <tbody> <tr> <th>Title</th> <td>A Tale of Two SOCs: Insights From Two Red Team Assessments</td> </tr> <tr> <th>Original Publication&nbsp;</th> <td><strong>August...
2026-07-14 CISA advisory
<p>CISA is aware of active exploitation of vulnerabilities <a href="https://www.cve.org/CVERecord?id=CVE-2026-32201" target="_blank">CVE-2026-32201</a>, <a href="https://www.cve.org/CVERecord?id=CVE-2026-45659"...
2022-03-03 CISA KEV
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT...
2026-07-23 CISA advisory
<div class="c-page-title__buttons"><a class="c-button" href="https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/1/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF">Russian State-Supported Cyber Actors Conduct Phishing...
2026-08-10 CISA advisory
<h2><strong>Advisory at a Glance</strong></h2> <table> <tbody> <tr> <th>Title</th> <td>#StopRansomware: Gunra Ransomware</td> </tr> <tr> <th>Original Publication</th> <td>August 10, 2026</td> </tr> <tr> <th>Executive...
2020-05-21 NVD CVE
A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code...
2026-01-26 CISA KEV
Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature...
2024-09-10 CISA KEV
Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of...
2023-07-11 CISA KEV
Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt.
2022-06-08 CISA KEV
Microsoft Word and Microsoft Works Suites contain a malformed object pointer which allows attackers to execute code.
2021-11-03 CISA KEV
Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an...
2026-08-26 CISA KEV
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
2026-08-21 CISA KEV
Microsoft Entra ID formerly known as Azure Active Directory contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
2026-08-20 NVD CVE
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
2026-08-20 NVD CVE
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
2026-08-20 NVD CVE
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
2026-08-18 CISA KEV
Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.
2026-08-18 CISA KEV
Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.
2026-08-18 CISA advisory
<p>CISA has added four new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation....
2026-08-11 CISA KEV
Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
2026-08-11 NVD CVE
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
2026-08-11 NVD CVE
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
2026-08-11 NVD CVE
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
2026-08-07 NVD CVE
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
2026-08-07 NVD CVE
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
2026-08-04 NVD CVE
Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
2026-07-24 NVD CVE
Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
2026-07-24 NVD CVE
Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.
2026-07-24 NVD CVE
Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.
2026-07-22 CISA KEV
Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
2026-07-16 CISA KEV
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
2026-07-15 News
Vulnerability counts have been surging this year, and Microsoft's mammoth disclosure this week of 622 bugs is larger than the three previous months combined.
2026-07-14 News
<p>The company forewarned customers and defenders that a flood of defects would be uncovered by AI. It delivered with a striking exponential increase.</p> <p>The post <a...
2026-07-14 NVD CVE
Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.
2026-07-14 CISA KEV
Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network.
2026-07-14 NVD CVE
Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.
2026-07-14 NVD CVE
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
2026-07-14 NVD CVE
Use after free in Microsoft Message Queuing Queue Manager allows an unauthorized attacker to execute code over a network.
2026-07-14 CISA advisory
<p>CISA has added four new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active...
◀ PREV PAGE 01 / 13 NEXT ▶