Power Automate For Desktop
6 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Power Automate For Desktop. Use it to gauge the current risk picture and drill into individual advisories.
Power Automate For Desktop CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 1 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 1 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 1 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 1 |
Severity
How the 6 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High3
- Medium2
Latest CVEs
The 6 most recently published vulnerabilities affecting Power Automate For Desktop.
- CVE-2026-77897Microsoft Power Automate Desktop Elevation of Privilege Vulnerability7.0
- CVE-2026-40374Microsoft Power Automate Desktop Information Disclosure Vulnerability6.5
- CVE-2025-47966Power Automate Elevation of Privilege Vulnerability9.8
- CVE-2025-29817Microsoft Power Automate Desktop Information Disclosure Vulnerability5.7
- CVE-2025-21187Microsoft Power Automate Remote Code Execution Vulnerability7.8
- CVE-2024-43479Microsoft Power Automate Desktop Remote Code Execution Vulnerability8.5
Product grouping is registry-driven, with AI assist and human review. How it works