CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-96207 — Improper certificate validation in Microsoft Partner Center allows an unauthoriz...

·Source: NIST NVD

Updated:

Executive Summary

Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

Analysis

Improper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network. CVSS Score: 10. Published: 2026-10-08T23:17:05.583.

Indicators of Compromise (1)

CVE (1)
CVE-2026-96207
Source Attribution

Originally published by NIST NVD on Oct 8, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-108707 — Wukong_HRM through commit 186115e contains an authentication bypass vulnerabilit...

Wukong_HRM through commit 186115e contains an authentication bypass vulnerability in ParamAspect that allows unauthenticated attackers to call every HRM API endpoint by omitting the AUTH-TOKEN header. Attackers gain HR administrator access to read payslips, salary history and employee personal data, download attachments, and modify or delete company-wide HR records.

CVE-2026-108707
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-108598 — Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateE...

Floci 1.1.0 before 2.2.0 contains a code injection vulnerability in VtlTemplateEngine that allows unauthenticated attackers to execute commands via unrestricted Velocity mapping templates. Attackers can create a REST API with a MOCK integration whose template uses $util reflection to reach Runtime or ProcessBuilder, executing OS commands in the Floci JVM.

CVE-2026-108598
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-108551 — openapi-typescript-codegen through 0.31.0 contains a code injection vulnerabilit...

openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript by supplying unescaped values interpolated into single-quoted string literals. Attackers can embed a single quote in path keys, parameter names, servers[0].url, or info.version to execute arbitrary JavaScript when generated clients are importe

CVE-2026-108551
NIST NVD