CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-62836: Azure SQL Managed Instance Elevation of Privilege Vulnerability

highCVSS 8.7CVE-2026-62836
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.

CSIRTS triage

What
Improper restriction of communication channels allows unauthorized attackers to elevate privileges over the network.
Who is affected
Deployments of Azure SQL Managed Instance are affected.
Urgency
High severity (CVSS 8.7); not yet exploited but requires timely patching.
Action
Apply the latest security update from Microsoft for Azure SQL Managed Instance.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Azure SQL Managed Instance

Get an email when a new Azure SQL Managed Instance advisory drops — max one per day, one-click unsubscribe.

Details

Source
Microsoft Security Response Center (INTL · vendor-psirt · site)
Severity
high — CVSS 8.7
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62836

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-62836coverage & exploitation statusNVD · CVE.org

More from Microsoft Security Response Center