CVE-2026-40379: Critical ESTS Spoofing Flaw in Azure Entra ID (Fixed, No Action)
Microsoft has fixed a critical vulnerability in its Enterprise Security Token Service (ESTS) that could have allowed attackers to spoof authentication tokens and gain unauthorized access to any Azure...