PatchDay Alert

CVE

CVE-2026-40379

0field notes · 1digest CVSS 9.3


Daily digests

Azure Entra ID (formerly Azure AD) leaks sensitive information to unauthenticated attackers, enabling spoofing over the network. CVSS 9.3. The practical risk: an attacker could impersonate identities or forge tokens in your tenant. This is an identity-plane bug, which makes it dangerous even if your apps are otherwise well-configured.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.