EU Vulnerability Database

EUVD Pulse

The latest critical and actively exploited vulnerabilities tracked by European authorities, updated hourly from the official EU Vulnerability Database.

EU Vulnerability Database (EUVD) Pulse

Official feed of the latest critical and actively exploited vulnerabilities tracked by European authorities.

Latest Critical Vulnerabilities

CVSS 9.0+
EUVD-2026-70795CVSS 10

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

9/3/2026microsoft
EUVD-2026-70794CVSS 9.3

Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.

9/3/2026microsoft
EUVD-2026-70793CVSS 10

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

9/3/2026microsoft
EUVD-2026-73812CVSS 9.8

Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.

9/8/2026microsoft

Actively Exploited (KEV)

In the wild
EUVD-2026-72530CVSS 10

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Exploited: 9/8/2026Adobe
EUVD-2026-72041CVSS 10

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

Exploited: 9/8/2026N-Able
EUVD-2026-73365CVSS 7.8

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

Exploited: 9/8/2026Microsoft
EUVD-2026-73889CVSS 7.8

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Exploited: 9/8/2026Microsoft