CVE-2026-66301
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose
CVSS
6.5
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 11, 2026 · Last modified: Aug 11, 2026 · CWE-200
Not enough EPSS history yet.
Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-73082——
———Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mcp-server/validate-agent-mcp-tool endpoint makes an outbound HTTP or SSE request to a user-supplied serverUrl without URL validation or SSRF protection. An authenticated user can cause the Activepieces server to connect to internal services, cloud metadata endpoints, or arbitrary external hosts and probe network reachability from the Activepieces host. This issue is fixed in version 0.82.0.6hCVE-2026-657696.5 MED—
———Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.6hCVE-2026-619246.5 MED—
———Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.6hCVE-2026-619216.5 MED—
———Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.6hCVE-2026-619186.5 MED—
———Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.6hCVE-2026-541235.5 MED—
———Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally.6h