Live Security Scan

Microsoft 365 vendor security report

Last scanned 19 hours ago

36
Overall risk score

CVE Activity

6
Total CVEs
6
Last 90 Days
0
KEV Exposed
3Critical2High1Medium0Low

SSL / TLS

Not yet scanned

DNS Security

Not yet scanned

Security Headers

Not yet scanned

Security & Breach News (last 12 months)

  • Critical Microsoft 365 Copilot Vulnerabilities Expose sensitive Information

    Microsoft disclosed three critical information disclosure vulnerabilities affecting Microsoft 365 Copilot and Copilot Chat that have been fully remediated. These vulnerabilities could have exposed sensitive information to unauthorized access.

    CyberSecurityNewsMay 12, 2026
    high
  • Critical SharePoint zero-day leaves 1,300+ servers exposed

    A critical zero-day vulnerability (CVE-2026-32201) in Microsoft SharePoint is being actively exploited in the wild, with over 1,300 server instances currently exposed. This represents a confirmed vulnerability with active exploitation against a Microsoft 365 component.

    MSNMay 8, 2026
    high
  • Microsoft's patch for a 0-day exploited by Russian spies fell short. Another Windows flaw is under attack

    Microsoft and CISA warned of an actively exploited zero-click Windows vulnerability that can expose systems to attack. The flaw represents a confirmed security incident affecting Windows systems, though the article indicates Microsoft's previous patch for a related 0-day was insufficient.

    The RegisterMay 6, 2026
    high
  • Microsoft Copilot privacy setting may pull data from other apps

    A Copilot privacy setting was identified that can access and pull data from other Microsoft services (Bing, MSN, Edge) to personalize responses, raising data handling and privacy concerns. This represents a configuration/privacy practice issue requiring investigation and potential user notification rather than a confirmed active breach.

    MSNMay 5, 2026
    medium
  • Salesforce and Slack sue Microsoft in UK for playing monopoly with Teams bundles

    Microsoft faces a UK antitrust lawsuit from Slack and Salesforce alleging anticompetitive bundling practices with Microsoft Teams. This is a regulatory/legal action rather than a security incident, but represents significant legal and compliance risk to the Microsoft 365 vendor.

    Windows CentralMay 5, 2026
    medium
  • Mandiant Exposes Hackers Impersonating Microsoft Teams Help Desk

    Mandiant identified UNC6692 threat actors exploiting Microsoft Teams to impersonate IT help desk personnel and deploy SNOW malware, with 77% of attacks targeting senior corporate staff. This represents a confirmed active incident leveraging Microsoft 365 infrastructure as an attack vector for credential theft and malware distribution.

    SQ MagazineMay 4, 2026
    high

Get weekly alerts when Microsoft 365's risk score changes

Track score changes, new CVEs, and breach news automatically.

Start free monitoring - no credit card

Monitor your complete vendor portfolio

Get daily risk scores, breach alerts, and compliance reports for all your SaaS tools.

Start free - 30 day trial