High CVSS: 8.0 CVE-2026-20960 Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.
Critical CVSS: 9.1 CVE-2025-47733 Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network