[CIVN-2026-0376] Multiple Vulnerabilities in Microsoft Products

By Published On: July 23, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Microsoft Products


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Dynamics 365 Customer Voice 

Microsoft 365 Copilot

Microsoft Exchange Online

Azure Synapse

Microsoft Dynamics 365

Azure AI Bot Service

Microsoft Edge (Chromium-based)

Microsoft Cost Management

Overview


Multiple vulnerabilities have been reported in Microsoft Products, which could allow an attacker to perform spoofing, elevate privilege, perform tampering and disclose sensitive information on the targeted system.


Target Audience:

All end-user organizations and individuals using Microsoft Products.


Risk Assessment:

High risk of privilege escalation, spoofing, sensitive information disclosure.


Impact Assessment:

Potential for privilege escalation, spoofing, sensitive information disclosure and/or compromise of system.


Description


Multiple vulnerabilities have been reported in Microsoft Products due to improper neutralization of input during web page generation, URL redirection to untrusted site, missing authorization, execution with unnecessary privileges, improper access control, improper authentication, exposure of sensitive information, and improper neutralization of special elements in command. An attacker could exploit these vulnerabilities to perform spoofing, elevate privileges, perform tampering or disclose information over a network on the targeted system.


Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access, access sensitive information, elevate privileges, perform tampering over a network and/or perform spoofing on the targeted system.


Solution


Apply appropriate updates as mentioned by the vendor:

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47646


https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47645


https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48582


https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48584


https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47647


https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42895


https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32174


https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32208


https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47633



Vendor Information


Microsoft

https://www.microsoft.com/


References


 

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47646

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47645

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48582

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48584

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47647

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42895

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32174

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32208

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47633


CVE Name

CVE-2026-47646

CVE-2026-47645

CVE-2026-48582

CVE-2026-48584

CVE-2026-47647

CVE-2026-42895

CVE-2026-32174

CVE-2026-32208

CVE-2026-47633




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpiKmgACgkQ3jCgcSdc

ys+aSw//SMiGExXx/tZvxEEcCrDhCcyAjhUf2MVpTpn57H2qCH5cwiD+ksoW34pl

MpO0DGKwzdehsuF0nf4GmtJlXwAOBWiLvg/ETcmVIeFYr76URABrvJccDL+ntT1p

qnondxNJotSUm1kldWB9omttck8WC+OOjJ2fO6ACkwWb0P+TFqSaBtC+HsySJ53i

td0/fsHYl2iX1Zq+eQjnyCPpYUADkA57av0qCrBQznV3ktjjYh0MvW+H2iH5bjy7

tQoljaPQxDC43DJJr5f3Nfw/NJstgX6MhgETx08LUPlvQ7t/lIKnP2PPQldkg2WT

xqfUjAbjXEidbh4+4YqpsoRFwZfXdsm1GMdrmZPu13BHaJztmGbnII/dCKpW1Gs2

elxEiMuY4sB9GrMqtomAZSV8GgkBFXzwUUtk50NpwqkHt/0GlJP1cGzusBbhdwdT

baFzs8Ayzfs4cU6hqnSk7ehGJc3IHdFVpW0YOpOEyxgNGZVA63mJbw5HSZ6BWEcQ

2V7BhmQ5TwCxZf2VRE2kVhcYt+js0VNZmGw+IPVdN2Ory1tVWouHkZMqdH4DgkQf

BQns5ssxlDksRjxzGLwbiGIXhiUkeBTK/hKjQmsq/YsldVnWOwLwv1v7mjYpqSP5

TqUiC709WB+kbgnyc1bnw9qm520qZZmY6vg20s6vWCx+VajICMw=

=zaXX

—–END PGP SIGNATURE—–

Share this article