CVE-2026-40379
Microsoft · Published May 7, 2026
9.3
CVSS v3.1
CRITICALPatch availableGet patch
Description
Azure Entra ID Spoofing Vulnerability. Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
Affected Products
- Microsoft Entra ID
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C