
[CIVN-2026-0376] Multiple Vulnerabilities in Microsoft Products
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Microsoft Products
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Dynamics 365 Customer Voice
Microsoft 365 Copilot
Microsoft Exchange Online
Azure Synapse
Microsoft Dynamics 365
Azure AI Bot Service
Microsoft Edge (Chromium-based)
Microsoft Cost Management
Overview
Multiple vulnerabilities have been reported in Microsoft Products, which could allow an attacker to perform spoofing, elevate privilege, perform tampering and disclose sensitive information on the targeted system.
Target Audience:
All end-user organizations and individuals using Microsoft Products.
Risk Assessment:
High risk of privilege escalation, spoofing, sensitive information disclosure.
Impact Assessment:
Potential for privilege escalation, spoofing, sensitive information disclosure and/or compromise of system.
Description
Multiple vulnerabilities have been reported in Microsoft Products due to improper neutralization of input during web page generation, URL redirection to untrusted site, missing authorization, execution with unnecessary privileges, improper access control, improper authentication, exposure of sensitive information, and improper neutralization of special elements in command. An attacker could exploit these vulnerabilities to perform spoofing, elevate privileges, perform tampering or disclose information over a network on the targeted system.
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access, access sensitive information, elevate privileges, perform tampering over a network and/or perform spoofing on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47646
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47645
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48582
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48584
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47647
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42895
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32174
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32208
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47633
Vendor Information
Microsoft
https://www.microsoft.com/
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47646
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47645
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48582
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48584
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47647
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42895
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32174
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32208
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47633
CVE Name
CVE-2026-47646
CVE-2026-47645
CVE-2026-48582
CVE-2026-48584
CVE-2026-47647
CVE-2026-42895
CVE-2026-32174
CVE-2026-32208
CVE-2026-47633
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpiKmgACgkQ3jCgcSdc
ys+aSw//SMiGExXx/tZvxEEcCrDhCcyAjhUf2MVpTpn57H2qCH5cwiD+ksoW34pl
MpO0DGKwzdehsuF0nf4GmtJlXwAOBWiLvg/ETcmVIeFYr76URABrvJccDL+ntT1p
qnondxNJotSUm1kldWB9omttck8WC+OOjJ2fO6ACkwWb0P+TFqSaBtC+HsySJ53i
td0/fsHYl2iX1Zq+eQjnyCPpYUADkA57av0qCrBQznV3ktjjYh0MvW+H2iH5bjy7
tQoljaPQxDC43DJJr5f3Nfw/NJstgX6MhgETx08LUPlvQ7t/lIKnP2PPQldkg2WT
xqfUjAbjXEidbh4+4YqpsoRFwZfXdsm1GMdrmZPu13BHaJztmGbnII/dCKpW1Gs2
elxEiMuY4sB9GrMqtomAZSV8GgkBFXzwUUtk50NpwqkHt/0GlJP1cGzusBbhdwdT
baFzs8Ayzfs4cU6hqnSk7ehGJc3IHdFVpW0YOpOEyxgNGZVA63mJbw5HSZ6BWEcQ
2V7BhmQ5TwCxZf2VRE2kVhcYt+js0VNZmGw+IPVdN2Ory1tVWouHkZMqdH4DgkQf
BQns5ssxlDksRjxzGLwbiGIXhiUkeBTK/hKjQmsq/YsldVnWOwLwv1v7mjYpqSP5
TqUiC709WB+kbgnyc1bnw9qm520qZZmY6vg20s6vWCx+VajICMw=
=zaXX
—–END PGP SIGNATURE—–


