Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 03 Feb 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft account
|
|
| CPEs | cpe:2.3:a:microsoft:account:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft account
|
Fri, 23 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 22 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Account allows an unauthorized attacker to perform spoofing over a network. | |
| Title | Microsoft Account Spoofing Vulnerability | |
| First Time appeared |
Microsoft
Microsoft micrososft Account |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:microsoft:micrososft_account:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft micrososft Account |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-04-01T13:49:27.520Z
Reserved: 2025-12-11T21:02:05.738Z
Link: CVE-2026-21264
Updated: 2026-01-23T20:02:56.629Z
Status : Analyzed
Published: 2026-01-22T23:15:57.407
Modified: 2026-02-03T12:58:31.007
Link: CVE-2026-21264
No data.
OpenCVE Enrichment
Updated: 2026-04-16T18:00:11Z