CVE-2026-49159 Microsoft Graph Information Disclosure Vulnerability Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. EPSS 0.01 CVE-2026-49159 Microsoft US Microsoft Security · 23. 7. 16:00