Microsoft Azure Active Directory — known CVE vulnerabilities
Every CVE whose affected-product data names Microsoft Azure Active Directory, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (6)
CVE-2026-45480 — CVSS 10.0 (critical): Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
CVE-2026-50481 — CVSS 9.9 (critical): Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
CVE-2021-42306 — CVSS 8.1 (high): An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an…
CVE-2026-50652 — CVSS 7.5 (high): Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
CVE-2026-50653 — CVSS 7.5 (high): Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a…