CVE-2026-32172Disclosure(microsoft / power_apps)

LOWCVSS 8.0 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch microsoft power_apps systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-427

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • power_apps

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-24); latest day: 2
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
power_apps

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 3d
01122Mentions · 2026-04-24: 2Mentions · 2026-04-25: 2Mentions · 2026-04-27: 2Patch / Workaround · 2026-04-25: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 2Technical Details · 2026-04-27: 204-2404-2504-27
Signal classification2 categories
Disclosure
583.3%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-242
Disclosure2
2026-04-252
Disclosure1Patch1
2026-04-272
Disclosure2
Full discourse6 posts
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 2026. 4.23 Microsoft Power Apps のリモートでコードが実行される脆弱性 CVE-2026-32172 Security Vulnerability リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32172

    Post summary

    Microsoft announced a new remote code execution vulnerability (CVE-2026-32172) affecting Power Apps, providing only basic CVE details without PoC, exploit code, or patch information.

    10100112
    85 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 CVE-2026-32172 「脆弱性を解決するために、お客様が取るべきアクション…」 影響: リモートでコードが実行される 最大深刻度: 緊急 CVSS:3.1 8.0 / 7.0 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 対象外 https://x.com/kawn2020/status/2048672920621498460

    Post summary

    The tweet announces a new Microsoft vulnerability (CVE‑2026‑32172) that can lead to remote code execution, assigns it an emergency severity rating, provides CVSS scores, and reports no public exploitation or PoC.

    1000057
    85 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32172 Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network. https://www.cve.org/CVERecord?id=CVE-2026-32172

    Post summary

    CVE‑2026‑32172 is an uncontrolled search path element vulnerability in Microsoft Power Apps that can lead to remote code execution, as documented in the linked CVE record.

    00000118
    57.3K followersView on X
  • cybersecuritypath@cybrsecpath
    Patch

    CVE-2026-32172: Critical Microsoft Power Apps RCE Fully Fixed https://thecybrdef.com/cve-2026-32172-microsoft-power-apps-rce-vulnerability/ #CVE202632172 #MicrosoftPowerApps #CyberSecurity

    Post summary

    CVE-2026-32172 is a critical remote code execution vulnerability in Microsoft Power Apps that has been fully patched, with no indication of active exploitation or PoC availability.

    0000065
    6 followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-32172 | Microsoft Power Apps Remote Code Execution Vulnerability https://www.aakashrahsi.online/post/cve-2026-32172 https://t.co/9wmOqCaTdB

    Post summary

    A CVE-2026-32172 vulnerability is announced as a Remote Code Execution flaw in Microsoft Power Apps, with only a link to a blog post provided and no further technical, exploit, or mitigation details.

    0000033
    1 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Microsoft Power Apps (CVE-2026-32172) https://vuldb.com/vuln/359228

    Post summary

    A severe vulnerability has been disclosed for Microsoft Power Apps, but no additional technical details, exploit code, or mitigation guidance are provided in the text.

    0000077
    2.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftpower_apps---

Explore more