Multiple vulnerabilities in Microsoft Azure Linux (July 15, 2026)
Multiple vulnerabilities have been discovered in Microsoft Azure Linux. They allow an attacker to cause an unspecified security issue by the vendor.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to cause an unspecified security issue by the vendor.
- Who is affected
- Deployments of Microsoft Azure Linux are affected.
- Urgency
- Remediation is urgent due to the unspecified nature of the security issues.
- Action
- Apply patches as they become available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Azure Linux
Get an email when a new Azure Linux advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0873/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-143800.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all scored CVEs.
- Low exploitation riskCVE-2026-144610.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-599960.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all scored CVEs.
- Low exploitation riskCVE-2026-599950.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all scored CVEs.
- Low exploitation riskCVE-2026-599990.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-202160.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all scored CVEs.
- Low exploitation riskCVE-2026-580130.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all scored CVEs.
- Low exploitation riskCVE-2026-89260.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
- Low exploitation riskCVE-2026-202430.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all scored CVEs.
- Low exploitation riskCVE-2026-84580.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Red Hat Enterprise Linux (sssd, glib, c-ares): Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] vim: Multiple vulnerabilities allow code executioncert-bund
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)cert-fr-avis
- medium[NEW] [medium] X.Org X11 Server (libXfont2): Multiple vulnerabilities allow execution of arbitrary code with a…cert-bund
- medium[UPDATE] [medium] cURL: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] cURL: Multiple vulnerabilitiescert-bund
- high[NEW] [high] X.Org X11 and Xwayland: Multiple vulnerabilities allow code execution and DoScert-bund
- medium[UPDATE] [medium] ClamAV: Multiple vulnerabilitiescert-bund
- mediumGHSA-h35f-9h28-mq5c: setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NF…ghsa
- unknownUSN-8560-1: libXfont vulnerabilitiesubuntu
- medium[NEW] [medium] Erlang/OTP: Multiple vulnerabilitiescert-bund
- unknownDSA-6388-1 libxfont - security updatedebian
Recent advisories for Microsoft Azure Linux
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownMultiple vulnerabilities in Microsoft Azure Linux (July 10, 2026)cert-fr-avis · 2026-07-10
- unknownMultiple vulnerabilities in Microsoft Azure Linux (July 09, 2026)cert-fr-avis · 2026-07-09
- unknownMultiple vulnerabilities in Microsoft Azure Linux (July 7, 2026)cert-fr-avis · 2026-07-07
- unknownMultiple vulnerabilities in Microsoft Azure Linux (June 29, 2026)cert-fr-avis · 2026-06-29
- unknownMultiple vulnerabilities in Microsoft Azure Linux (June 25, 2026)cert-fr-avis · 2026-06-25
- unknownMultiple vulnerabilities in Microsoft Azure Linux (June 24, 2026)cert-fr-avis · 2026-06-24
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Red Hat (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)2026-07-31