Multiple vulnerabilities in Microsoft Azure Linux (July 7, 2026)
Multiple vulnerabilities have been discovered in Microsoft Azure Linux. They allow an attacker to cause an unspecified security issue by the vendor.
CSIRTS triage
- What
- Multiple vulnerabilities allow for unspecified security issues.
- Who is affected
- Deployments of Microsoft Azure Linux are affected.
- Urgency
- The urgency is unclear due to the unspecified nature of the vulnerabilities.
- Action
- Check for updates and apply any available patches.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Microsoft Azure Linux
Get an email when a new Microsoft Azure Linux advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0841/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-135950.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2025-156611.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 61% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-142580.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-31960.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-116230.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-415790.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-116250.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-580580.88% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-551990.92% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 57% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-13595 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-15661 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-14258 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-3196 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-11623 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-41579 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-11625 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58058 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55199 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] libssh2: Vulnerability allows Denial of Service and disclosure of informationcert-bund
- high[UPDATE] [high] libssh2: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] util-linux: Vulnerability enables denial of service and information disclosurecert-bund
- unknownMultiple vulnerabilities in Debian Linux kernel (August 21, 2026)cert-fr-avis
- medium[UPDATE] [medium] nmap: Vulnerability allows denial of servicecert-bund
- medium[NEW] [medium] dhcpcd: Vulnerability enables Denial of Servicecert-bund
- unknownDSA-6442-1 util-linux - security updatedebian
- lowCVE-2026-41579: runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violatio…msrc
- mediumCVE-2026-14258: Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router a…msrc
- mediumCVE-2026-14258: A flaw was found in dhcpcd's IPv6 Neighbor Discovery Router Advertisement processing. A specia…nvd
- lowCVE-2026-41579: runc is a CLI tool for spawning and running containers according to the OCI specification. In …nvd
- mediumCVE-2026-13595: A flaw was found in the libblkid library of util-linux. During nested partition probing, the B…nvd
Recent advisories for Microsoft Azure Linux
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownMultiple vulnerabilities in Microsoft Azure Linux (July 15, 2026)cert-fr-avis · 2026-07-15
- unknownMultiple vulnerabilities in Microsoft Azure Linux (July 10, 2026)cert-fr-avis · 2026-07-10
- unknownMultiple vulnerabilities in Microsoft Azure Linux (July 09, 2026)cert-fr-avis · 2026-07-09
- unknownMultiple vulnerabilities in Microsoft Azure Linux (June 29, 2026)cert-fr-avis · 2026-06-29
- unknownMultiple vulnerabilities in Microsoft Azure Linux (June 25, 2026)cert-fr-avis · 2026-06-25
- unknownMultiple vulnerabilities in Microsoft Azure Linux (June 24, 2026)cert-fr-avis · 2026-06-24
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21