
[CIVN-2026-0403] Multiple Vulnerabilities in Microsoft Products
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Microsoft Products
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Azure SQL Managed Instance
Microsoft Teams
Microsoft Purview eDiscovery
Microsoft Power Apps
Azure Active Directory
Microsoft Entra Provisioning Service
Microsoft Application Insights Profiler
Azure Confidential Ledger
Azure Logic Apps
Azure SRE Agent
Azure SQL Database
Azure Service Bus
Microsoft Planetary Computer Pro
Microsoft 365 Admin Center
Microsoft Office SharePoint
Overview
Multiple vulnerabilities have been reported in Microsoft Products, which could allow an attacker to perform spoofing, elevate privilege, perform tampering and disclose sensitive information on the targeted system.
Target Audience:
All end-user organizations and individuals using the Microsoft Products.
Risk Assessment:
High risk of privilege escalation, spoofing, sensitive information disclosure.
Impact Assessment:
High impact on Confidentiality, Integrity and Availability of the affected systems.
Description
Multiple vulnerabilities have been reported in Microsoft Products due to broken authorization/authentication controls, improper access control, modification of data assumed to be immutable, unsafe exposure of privileged functionality, or inadequate path handling.
An attacker could exploit these vulnerabilities by sending crafted network requests, abusing authentication or authorization weaknesses, manipulating paths or resource handling and invoking exposed privileged functionality.
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to protected information, privilege escalation and remote code execution.
Solution
Apply appropriate updates as mentioned by the vendor:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62836
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62896
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65668
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59118
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50481
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62918
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59115
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49163
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68823
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56161
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62830
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65667
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56162
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50515
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63508
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62873
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70332
Vendor Information
Micosoft
https://www.microsoft.com/
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62836
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62896
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65668
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59118
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50481
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62918
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59115
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49163
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68823
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56161
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62830
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65667
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56162
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50515
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63508
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62873
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70332
CVE Name
CVE-2026-62836
CVE-2026-62896
CVE-2026-65668
CVE-2026-59118
CVE-2026-50481
CVE-2026-62918
CVE-2026-59115
CVE-2026-49163
CVE-2026-68823
CVE-2026-56161
CVE-2026-62830
CVE-2026-65667
CVE-2026-56162
CVE-2026-50515
CVE-2026-63508
CVE-2026-62873
CVE-2026-70332
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmp7KI0ACgkQ3jCgcSdc
ys9xIQ/+Ibmw21ing3z0sEWAlyLVFhtQeqNEN/p+J1oJ0qxTrjv4N3IWmdna18jx
URA1d8h0oNutyHIrq+YI8Vjt2FY6Ij62AisNa0A6lnTN4X867cn3xXl9P/KvKw1u
M77Co/JAjS4yxp8l8mFQUvG0ruu98MGfHQXbHl5t4YjFYxnQQsjPB3uAxN/7Dbn+
4tRHQWAjHFN0J7Q1X57JlGfd/6jGRO0KSoby+xO5Lw5VsV6QyPWQw+9klS8nEeFl
MZQQbm/5FWjaQU30Ae5ECZrpJ5A+Ckvr+tcKda/UP55pNqodmtfsRAgNVyV4m8gz
kUXDj0fuzCsWk7dOYOQPbg/seJND8/661p1LUm9QioArP+kU7fP2N0rIvRy7YlrJ
6Oc070YlTJZke2TAN6ogJJmcZ08yEAoZan8P6nnACIcMS1dBKR0XYf7yTMVANu5M
CnNic2z89Y2pvpYWvyBTO6463HSpeQ7gnftRepvikEVC+QwLAxlIQ1OJAikOSbZ6
Jq/ZIXyl2LjEWW+GS7XPgeNlpg6NBUIPck1zbKzsYHQc8qSEBDTmFdGbg05M6gtI
30ddZQL2rmK+hFjHCTL1zBYalfj1wmW7kovhHVapnK20i9xkWAl8kRMlamlCCx22
QWfn/wUVNgsC4eHbUUkd7YvVbIhBnSxyU3epgTCxCS8hfDGSXJg=
=G1Ty
—–END PGP SIGNATURE—–


