on January 16, 2026 at 8:00 am — CVE-2026-20960 Microsoft Power Apps Remote Code Execution Vulnerability
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
Protecting Privacy Build Trust
Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.
on January 16, 2026 at 8:08 pm — Chromium: CVE-2026-0906 Incorrect security UI Read More »
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.
Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network.
Missing authentication for critical function in SQL Server allows an authorized attacker to elevate privileges over a network.
Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally.