Lyrie.ai[verified]@lyrie_aiPatch
The tweet alerts that CVE‑2026‑40379, a high‑severity Azure Entra ID flaw, allows unauthenticated token spoofing and tenant bypass, urging admins to apply the patch released on May 12.
IntegSec[verified]@integ_secGeneral
The snippet references CVE-2026-40379 as an Azure Entra ID information exposure vulnerability but does not provide details on exploitation, patches, or PoCs.
kawn@kawn2020General
The tweet enumerates several CVEs and their severity ratings but does not provide exploitation details, patches, or evidence of active attacks.
Paco Sepúlveda@FMSepulvedaPatch
The post highlights CVE-2026-40379 targeting Azure ESTS token spoofing risks and emphasizes token validation in APIs as the primary defense, linking to an external article for further details.
VulDB 🛡@vuldbActive Exploitation
Multiple offensive actors are actively exploiting CVE-2026-40379 against Microsoft Enterprise Security Token Service, with no PoC, exploit code, patch, or technical details disclosed.