Entra Id

Vendor:

First CVE: Aug 23, 2024 · Active for 1 year

9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
9.5
Avg CVSS
Higher Avg CVSS than 87% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Entra Id over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 23, 2024
23 months ago
Most Recent CVE
May 22, 2026
64 days ago

CVE Severity & Scoring

Entra Id9 CVEs
All CVEs352,708 CVEs
HighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (77.8%)
Unknown0 (0.0%)
Required2 (22.2%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
May 22, 202610.042NONO
Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.
May 22, 20269.841NONO
Azure Entra ID Elevation of Privilege Vulnerability
Oct 9, 20259.839NONO
Azure Entra ID Elevation of Privilege Vulnerability
Sep 4, 202510.039NONO
Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.
May 12, 20269.335NONO
Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.
Apr 23, 202610.035NONO
Azure Entra ID Elevation of Privilege Vulnerability
Oct 9, 20259.634NONO
Azure Entra ID Elevation of Privilege Vulnerability
Jan 22, 20269.833NONO
Improper access control in Decentralized Identity Services resulted in a vulnerability that allows an unauthenticated attacker to disable Verifiable ID's on another tenant.
Aug 23, 20247.523NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Entra Id

Top CWEs

Versions

No cataloged versions.