Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | CVE-2026-69857 Azure Cosmos DB Spoofing Vulnerability | 0 | 10.42 | 03-09-2026 |
| 2 | «Десятка» по CVSS: что скрывается за уязвимостью в облаке Microsoft и кому она действительно грозит | -1 | 8.79 | 27-08-2026 |
| 3 | NetScaler CVE-2026-19490 Lets Attackers Bypass Authentication | 0 | 7.33 | 19-08-2026 |
| 4 | Microsoft Confirms Windows Defender Flaw That Could Give Attackers Full SYSTEM Access | 0 | 8 | 04-07-2026 |
| 5 | Cosmos EVM: уязвимость в обработке балансов использована на шести блокчейнах | -1 | 13.63 | 29-08-2026 |
| 6 | It took $58 to break Microsoft’s SCCM, but a patch made it harder | 0 | 12.46 | 13-08-2026 |
| 7 | Cosmos Labs warns of security incident affecting Cosmos EVM module users | 0 | 7.97 | 25-08-2026 |
| 8 | Microsoft patches LegacyHive Windows zero-day vulnerability | 0 | 14.69 | 13-08-2026 |
| 9 | August’s Patch Tuesday is a monster: 751 fixes, with an exploited Windows flaw | 0 | 20.98 | 14-08-2026 |