CyberICT

CVE-2026-40379

Microsoft · Published May 7, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Azure Entra ID Spoofing Vulnerability. Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.

Affected Products

  • Microsoft Entra ID

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C