CVE-2025-21187: Microsoft Power Automate For Desktop

High severity, CVSS 7.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Microsoft Power Automate Remote Code Execution Vulnerability

Affected products

  • Microsoft Power Automate For Desktop: from 2.46, before 2.46.184.25013 (fixed in 2.46.184.25013); from 2.47, before 2.47.126.25010 (fixed in 2.47.126.25010); from 2.48, before 2.48.164.25010 (fixed in 2.48.164.25010); from 2.49, before 2.49.182.25010 (fixed in 2.49.182.25010); from 2.50, before 2.50.139.25010 (fixed in 2.50.139.25010); from 2.51, before 2.51.349.24355 (fixed in 2.51.349.24355)

Published 2025-01-14. Last modified 2026-06-17.