NCSC-2026-0233 [1.00] [M/H] Vulnerabilities fixed in Microsoft Azure
Microsoft has fixed vulnerabilities in various Azure components. An attacker can exploit the vulnerabilities to cause a Denial-of-Service, bypass security measures, or grant themselves elevated privileges, potentially gaining access to data to which the attacker was initially not authorized. The most severe vulnerabilities were found in the OpenAI agent and Entra provisioning. However, these vulnerabilities have already been centrally fixed by Microsoft and are included for information only. No actions are required for these vulnerabilities.
CSIRTS triage
- What
- Vulnerabilities can cause Denial-of-Service, bypass security measures, or grant elevated privileges.
- Who is affected
- Users of various Microsoft Azure components.
- Urgency
- Remediation is necessary as these vulnerabilities could lead to significant impacts, although no exploitation has been reported.
- Action
- Review the advisories and apply the necessary updates for the affected Azure components.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Azure
Get an email when a new Azure advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0233
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-579690.53% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all scored CVEs.
- Low exploitation riskCVE-2026-582790.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all scored CVEs.
- Low exploitation riskCVE-2026-571000.65% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all scored CVEs.
- Low exploitation riskCVE-2026-476320.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
- Low exploitation riskCVE-2026-503380.47% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all scored CVEs.
- Moderate exploitation riskCVE-2026-506521.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 64% of all scored CVEs.
- Low exploitation riskCVE-2026-506530.78% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all scored CVEs.
- Low exploitation riskCVE-2026-454990.61% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all scored CVEs.
- Low exploitation riskCVE-2026-261450.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-57969 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58279 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-57100 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47632 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50338 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50652 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50653 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-45499 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-26145 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Microsoft Azure: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Microsoft Azure (July 15, 2026)cert-fr-avis
- mediumCVE-2026-58279: Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges …nvd
- highCVE-2026-57969: Missing authentication for critical function in Azure CycleCloud allows an authorized attacker…nvd
- highCVE-2026-50653: Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an una…nvd
- highCVE-2026-50652: Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to…nvd
- highCVE-2026-50338: Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileg…nvd
- highCVE-2026-47632: Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elev…nvd
- criticalCVE-2026-57100: Microsoft Entra Provisioning Service Elevation of Privilege Vulnerabilitymsrc
- highCVE-2026-57969: Azure CycleCloud Elevation of Privilege Vulnerabilitymsrc
- highCVE-2026-50653: Azure Active Directory Denial of Service Vulnerabilitymsrc
- highCVE-2026-47632: Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerabilitymsrc
Recent advisories for Microsoft Azure
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownVulnérabilité dans Microsoft Azure (31 juillet 2026)cert-fr-avis · 2026-07-31
- high[NEW] [high] Microsoft Azure Portal: Vulnerability allows information disclosurecert-bund · 2026-07-28
- high[NEW] [high] Microsoft Azure, Copilot, Exchange, Surface: Multiple vulnerabilitiescert-bund · 2026-07-27
- criticalCVE-2026-56163: Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an u…nvd · 2026-07-24
- criticalCVE-2025-66390: In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/passw…nvd · 2026-07-21
- unknownCVE-2026-54733: The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Activ…nvd · 2026-07-16
More from NCSC-NL Advisories
- unknownNCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk2026-07-31
- unknownNCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic2026-07-31
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory2026-07-31
- unknownNCSC-2026-0271 [1.00] [M/H] Vulnerability fixed in Cisco Secure Firewall Management Center2026-07-30
- unknownNCSC-2026-0270 [1.00] [M/M] Vulnerabilities fixed in GitLab by GitLab Inc.2026-07-30