CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0287 [1.00] [M/H] Vulnerabilities fixed in Microsoft Azure

unknownCVE-2026-56162CVE-2026-50516CVE-2026-56161CVE-2026-59115CVE-2026-62830CVE-2026-62873
Microsoft has fixed vulnerabilities in various Azure components. A malicious actor can exploit the vulnerabilities to perform attacks that can lead to the damage categories listed in the table below. The vulnerability identified as CVE-2026-56162, with a CVSS score of 10.0 and the vulnerabilities identified as CVE-2026-50516, CVE-2026-56161, CVE-2026-59115, CVE-2026-62830, CVE-2026-62873 and CVE-2026-68823, each with a CVSS score higher than 9, have already been centrally fixed by Microsoft itself and are only included for information. No actions are required for these. The vulnerability identified as CVE-2026-50481, with a CVSS score of 9.9 however, does require action. This vulnerability is located in Azure Active Directory and enables a malicious actor to escalate privileges and thereby gain access to data and components to which the malicious actor was not initially authorized. Azure Monitor Agent: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-47299 | 7.20 | Obtaining elevated privileges | |----------------|------|-------------------------------------| Microsoft Purview eDiscovery: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-65668 | 8.80 | Obtaining elevated privileges | |----------------|------|-------------------------------------| Microsoft Azure Kubernetes Service: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-50516 | 9.40 | Obtaining elevated privileges | |----------------|------|-------------------------------------| Azure Entra ID: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impa

CSIRTS triage

What
Multiple vulnerabilities across Azure components, with CVE-2026-50481 in Azure Active Directory enabling privilege escalation to access unauthorized data and components.
Who is affected
Organizations using Microsoft Azure, particularly those with Azure Active Directory deployments.
Urgency
Critical for CVE-2026-50481 (CVSS 9.9); it directly enables privilege escalation in Azure AD and requires immediate action, while other listed CVEs have been centrally patched by Microsoft.
Action
Apply Microsoft's fix for CVE-2026-50481 in Azure Active Directory; note that CVE-2026-56162, CVE-2026-50516, CVE-2026-56161, CVE-2026-59115, CVE-2026-62830, CVE-2026-62873, and CVE-2026-68823 are already centrally remediated.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Azure

Get an email when a new Azure advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-08-12
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0287

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-56162coverage & exploitation statusNVD · CVE.org
CVE-2026-50516coverage & exploitation statusNVD · CVE.org
CVE-2026-56161coverage & exploitation statusNVD · CVE.org
CVE-2026-59115coverage & exploitation statusNVD · CVE.org
CVE-2026-62830coverage & exploitation statusNVD · CVE.org
CVE-2026-62873coverage & exploitation statusNVD · CVE.org
CVE-2026-68823coverage & exploitation statusNVD · CVE.org
CVE-2026-50481coverage & exploitation statusNVD · CVE.org
CVE-2026-47299coverage & exploitation statusNVD · CVE.org
CVE-2026-65668coverage & exploitation statusNVD · CVE.org
CVE-2026-62869coverage & exploitation statusNVD · CVE.org
CVE-2026-65673coverage & exploitation statusNVD · CVE.org
CVE-2026-63522coverage & exploitation statusNVD · CVE.org
CVE-2026-49163coverage & exploitation statusNVD · CVE.org
CVE-2026-70340coverage & exploitation statusNVD · CVE.org
CVE-2026-65806coverage & exploitation statusNVD · CVE.org
CVE-2026-57104coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Microsoft Azure

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories