Multiple vulnerabilities in Microsoft Azure (August 12, 2026)
Multiple vulnerabilities have been discovered in Microsoft Azure. They allow an attacker to cause privilege escalation, breach of data confidentiality and security policy bypass.
CSIRTS triage
- What
- Multiple vulnerabilities in Microsoft Azure allow privilege escalation, data confidentiality breach, and security policy bypass.
- Who is affected
- Microsoft Azure deployments and users on affected service versions.
- Urgency
- High priority; privilege escalation and policy bypass are critical control circumventions.
- Action
- Review Microsoft security updates for Azure and apply patches to affected subscriptions and infrastructure.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Azure
Get an email when a new Azure advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1003/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-571040.81% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-703400.58% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-472990.94% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 58% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-67260.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-658060.59% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-67270.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-57104 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70340 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47299 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6726 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65806 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-6727 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Microsoft Azure and Entra ID: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0287 [1.00] [M/H] Vulnerabilities fixed in Microsoft Azurencsc-nl
- unknownexploitedNCSC-2026-0284 [1.00] [M/H] Vulnerabilities patched in Microsoft Windowsncsc-nl
- highCVE-2026-70340: Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges …nvd
- mediumCVE-2026-65806: Missing authorization in Azure CycleCloud allows an authorized attacker to disclose informatio…nvd
- highCVE-2026-57104: Improper neutralization of input during web page generation ('cross-site scripting') in Azure …nvd
- highCVE-2026-47299: Improper neutralization of special elements used in a command ('command injection') in Azure M…nvd
- mediumCVE-2026-6727: A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privile…nvd
- highCVE-2026-6726: An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could …nvd
- highCVE-2026-57104: Azure Storage Explorer Elevation of Privilege Vulnerabilitymsrc
- mediumCVE-2026-65806: Azure CycleCloud Information Disclosure Vulnerabilitymsrc
- highCVE-2026-47299: Azure Monitor Agent Elevation of Privilege Vulnerabilitymsrc
Recent advisories for Microsoft Azure
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Microsoft Azure and Entra ID: Multiple vulnerabilitiescert-bund · 2026-08-12
- unknownNCSC-2026-0287 [1.00] [M/H] Vulnerabilities fixed in Microsoft Azurencsc-nl · 2026-08-12
- highCVE-2026-71331: Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attest…nvd · 2026-08-11
- highCVE-2026-66802: Concurrent execution using shared resource with improper synchronization ('race condition') in…nvd · 2026-08-11
- criticalCVE-2026-50516: Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an u…nvd · 2026-08-11
- criticalCVE-2026-50516: Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerabilitymsrc · 2026-08-11
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Debian Linux kernel (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Elastic Kibana (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in Netgate products (August 14, 2026)2026-08-14
- unknownMultiple vulnerabilities in SUSE Linux kernel (August 14, 2026)2026-08-14
- unknownVulnerability in Sophos products (August 14, 2026)2026-08-14