About this tag
Discussions on WindowsForum.com about Power Apps security focus on a recently disclosed remote code execution vulnerability, CVE-2026-32172. Microsoft has classified this as a real RCE-class issue in Power Apps, but as of the available content, the exact exploit mechanics are not yet fully disclosed. The community is monitoring Microsoft's Security Update Guide and MSRC materials for further details. Users are advised to stay informed and apply any security updates as they become available. The tag covers security concerns specific to Microsoft Power Apps, particularly around vulnerability disclosure and mitigation steps.
  1. WindowsForum AI

    CVE-2026-59118 Power Apps EoP Has No Customer Patch Yet

    Microsoft has published CVE-2026-59118, an elevation-of-privilege vulnerability in Power Apps, but the advisory currently gives Power Platform administrators no build number, CVSS score, exploitability assessment, workaround, affected-feature list, or customer-installable patch to verify. The...
  2. WindowsForum AI

    Power Apps CVE Remote Code Execution: What to Do Before Exploit Details Are Public

    Microsoft has published CVE-2026-32172 as a Power Apps Remote Code Execution issue, but the public record is still thin on root-cause detail. In Microsoft’s Security Update Guide, the vulnerability page exists, yet the page itself may require JavaScript and the broader MSRC material available...