Multiples vulnérabilités dans Microsoft Azure (09 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1148/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-839480.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-698540.64% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-779090.59% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-628950.72% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-813490.72% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-83948 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-69854 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-77909 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62895 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-81349 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEU] [hoch] Microsoft Azure, Entra und Azure CLI : Mehrere Schwachstellencert-bund
- unknownNCSC-2026-0347 [1.00] [M/H] Kwetsbaarheden verholpen in Microsoft Azurencsc-nl
- highCVE-2026-83948: Improper neutralization of special elements used in a command ('command injection') in Microso…nvd
- highCVE-2026-81349: Improper neutralization of special elements used in an os command ('os command injection') in …nvd
- highCVE-2026-77909: Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disc…nvd
- criticalCVE-2026-69854: Improper authentication in Spring Cloud Azure allows an unauthorized attacker to elevate privi…nvd
- highCVE-2026-62895: Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized atta…nvd
- criticalCVE-2026-69854: Spring Cloud Azure Elevation of Privilege Vulnerabilitymsrc
- highCVE-2026-62895: Azure Arc SQL Server Extension Elevation of Privilege Vulnerabilitymsrc
- highCVE-2026-83948: Microsoft Azure CLI Remote Code Execution Vulnerabilitymsrc
- highCVE-2026-77909: Azure CycleCloud Information Disclosure Vulnerabilitymsrc
- highCVE-2026-81349: Azure HDInsight Ambari Elevation of Privilege Vulnerabilitymsrc
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans Microsoft Office (09 septembre 2026)2026-09-09
- unknownMultiples vulnérabilités dans les produits Microsoft (09 septembre 2026)2026-09-09
- unknownMultiples vulnérabilités dans Google Chrome (09 septembre 2026)2026-09-09
- unknownVulnérabilité dans les produits Cisco (09 septembre 2026)2026-09-09
- unknownVulnérabilité dans les produits ESET (09 septembre 2026)2026-09-09