Multiple vulnerabilities in Microsoft Azure (July 15, 2026)
Multiple vulnerabilities have been discovered in Microsoft Azure. They allow an attacker to cause remote arbitrary code execution, privilege escalation, and remote denial of service.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to cause remote arbitrary code execution, privilege escalation, and remote denial of service.
- Who is affected
- Deployments of Microsoft Azure are affected.
- Urgency
- Remediation is urgent due to the potential for remote code execution and denial of service.
- Action
- Apply patches as they become available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Azure
Get an email when a new Azure advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0871/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-550020.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-503380.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
- Low exploitation riskCVE-2026-506530.78% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all scored CVEs.
- Low exploitation riskCVE-2026-472950.92% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 57% of all scored CVEs.
- Moderate exploitation riskCVE-2026-506521.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 64% of all scored CVEs.
- Low exploitation riskCVE-2026-472960.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all scored CVEs.
- Low exploitation riskCVE-2026-579690.53% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all scored CVEs.
- Low exploitation riskCVE-2026-582790.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all scored CVEs.
- Low exploitation riskCVE-2026-476320.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-55002 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50338 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50653 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47295 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50652 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47296 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-57969 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58279 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47632 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Microsoft Azure: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Microsoft SQL Server and Power BI: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Microsoft products (July 15, 2026)cert-fr-avis
- unknownNCSC-2026-0233 [1.00] [M/H] Vulnerabilities fixed in Microsoft Azurencsc-nl
- unknownNCSC-2026-0232 [1.00] [M/H] Vulnerabilities fixed in Microsoft SQL Serverncsc-nl
- highCVE-2026-47295: Improper neutralization of special elements used in an sql command ('sql injection') in SQL Se…nvd
- mediumCVE-2026-58279: Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges …nvd
- highCVE-2026-57969: Missing authentication for critical function in Azure CycleCloud allows an authorized attacker…nvd
- highCVE-2026-55002: External control of file name or path in SQL Server allows an authorized attacker to elevate p…nvd
- highCVE-2026-50653: Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an una…nvd
- highCVE-2026-50652: Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to…nvd
- highCVE-2026-50338: Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileg…nvd
Recent advisories for Microsoft Azure
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownVulnérabilité dans Microsoft Azure (31 juillet 2026)cert-fr-avis · 2026-07-31
- high[NEW] [high] Microsoft Azure Portal: Vulnerability allows information disclosurecert-bund · 2026-07-28
- high[NEW] [high] Microsoft Azure, Copilot, Exchange, Surface: Multiple vulnerabilitiescert-bund · 2026-07-27
- criticalCVE-2026-56163: Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an u…nvd · 2026-07-24
- criticalCVE-2025-66390: In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/passw…nvd · 2026-07-21
- unknownCVE-2026-54733: The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Activ…nvd · 2026-07-16
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31