SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-65818

HIGH · CVSS 8.5 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-08

CyberRota Analysis

AI-Generated

Power Automate is vulnerable to a server-side request forgery (SSRF) flaw that enables authorized attackers to escalate privileges and potentially manipulate network resources. This high-severity vulnerability poses significant risks to organizations utilizing Power Automate for automation tasks, as it could lead to unauthorized access and data exposure. Organizations using this product should prioritize immediate remediation efforts to mitigate potential exploitation.

CVE
CVE-2026-65818
Severity
HIGH
CVSS
8.5
EPSS
0.33%

Original NVD Description

Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)