DevSecOps

Microsoft Patches Actively-Exploited MS PowerPages Flaw

Microsoft Logo on a Modern Glass Office Building

Updates have been issued by Microsoft to address a high-severity vulnerability impacting its website-building Software-as-a-Service (SaaS) platform Power Pages, which has already been leveraged in ongoing attacks, according to The Register.

Threat actors exploiting the flaw, tracked as CVE-2025-24989, could achieve privilege escalation in targeted networks and user registration control evasion to facilitate unauthorized site access, reported Microsoft, which noted the issue to impact only certain Power Pages users, who were urged to examine their websites for possible compromise. "If you've not been notified, this vulnerability does not affect you," Microsoft said.

Also fixed by Microsoft was a high-severity bug impacting the Bing search engine, tracked as CVE-2025-21355, which could be abused to facilitate remote code execution. While such a vulnerability has not yet been actively exploited by threat actors, Microsoft has acknowledged the existence of a proof-of-concept code that could be used in malicious activity.

You can skip this ad in 5 seconds

Cookies

This website uses cookies to improve your experience, provide social media features and deliver advertising offers that are relevant to you.

If you continue without changing your settings, you consent to our use of cookies in accordance with our privacy policy. You may disable cookies.