CVE-2026-87701 — CVSS 9.6 (critical): Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized…
CVE-2026-69857 — CVSS 8.5 (high): Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
CVE-2025-64675 — CVSS 8.3 (high): Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to…