CVE-2026-62895
Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVSS
8.8
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-89 · CWE-942 · CWE-1390
Not enough EPSS history yet.
Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-774838.8 HIG—
———Weak authentication in SQL Server allows an authorized attacker to elevate privileges over a network.2hCVE-2026-730259.8 CRI—
———Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.2hCVE-2026-697168.8 HIG—
———Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.2hCVE-2026-696366.5 MED—
———Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network.2hCVE-2026-673708.8 HIG—
———Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.2hCVE-2026-668208.8 HIG—
———Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.2h