CVE-2026-56161 — CVSS 9.6 (critical): Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
CVE-2026-32171 — CVSS 8.8 (high): Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
CVE-2026-21227 — CVSS 8.2 (high): Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to…