[NEU] [hoch] Microsoft Azure, Entra und Azure CLI : Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in Microsoft Azure, Microsoft Entra und Microsoft Azure CLI ausnutzen, um sich als andere Benutzer auszugeben, unberechtigt auf geschützte Daten und Funktionen zuzugreifen und diese zu verändern, erhöhte Berechtigungen bis hin zu SYSTEM-Rechten zu erlangen, beliebige Systembefehle bzw. Code mit den Rechten privilegierter Benutzer auszuführen sowie vertrauliche Informationen offenzulegen.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3265
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-698570.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-813490.72% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-837110.58% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-840030.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-839410.73% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-629160.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-839480.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-703520.62% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-779090.59% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-698540.64% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-69857 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81349 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-83711 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84003 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-83941 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62916 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-83948 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70352 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-77909 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-69854 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62895 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62906 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [hoch] Microsoft Clouddienste: Mehrere Schwachstellencert-bund
- unknownMultiples vulnérabilités dans les produits Microsoft (09 septembre 2026)cert-fr-avis
- unknownMultiples vulnérabilités dans Microsoft Azure (09 septembre 2026)cert-fr-avis
- unknownNCSC-2026-0347 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Azurencsc-nl
- highCVE-2026-84003: Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js…nvd
- highCVE-2026-83948: Improper neutralization of special elements used in a command ('command injection') in Microso…nvd
- criticalCVE-2026-83941: Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a n…nvd
- highCVE-2026-81349: Improper neutralization of special elements used in an os command ('os command injection') in …nvd
- highCVE-2026-77909: Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disc…nvd
- criticalCVE-2026-69854: Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privi…nvd
- highCVE-2026-62895: Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized atta…nvd
- criticalCVE-2026-83711: Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerabilitymsrc
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] OpenSSH: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10
- high[UPDATE] [hoch] OpenVPN: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] gzip: Mehrere Schwachstellen2026-09-10
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen2026-09-10