NCSC-2026-0287 [1.00] [M/H] Vulnerabilities fixed in Microsoft Azure
Microsoft has fixed vulnerabilities in various Azure components. A malicious actor can exploit the vulnerabilities to perform attacks that can lead to the damage categories listed in the table below. The vulnerability identified as CVE-2026-56162, with a CVSS score of 10.0 and the vulnerabilities identified as CVE-2026-50516, CVE-2026-56161, CVE-2026-59115, CVE-2026-62830, CVE-2026-62873 and CVE-2026-68823, each with a CVSS score higher than 9, have already been centrally fixed by Microsoft itself and are only included for information. No actions are required for these. The vulnerability identified as CVE-2026-50481, with a CVSS score of 9.9 however, does require action. This vulnerability is located in Azure Active Directory and enables a malicious actor to escalate privileges and thereby gain access to data and components to which the malicious actor was not initially authorized.
Azure Monitor Agent: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-47299 | 7.20 | Obtaining elevated privileges | |----------------|------|-------------------------------------| Microsoft Purview eDiscovery: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-65668 | 8.80 | Obtaining elevated privileges | |----------------|------|-------------------------------------| Microsoft Azure Kubernetes Service: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impact | |----------------|------|-------------------------------------| | CVE-2026-50516 | 9.40 | Obtaining elevated privileges | |----------------|------|-------------------------------------| Azure Entra ID: |----------------|------|-------------------------------------| | CVE-ID | CVSS | Impa
CSIRTS triage
- What
- Multiple vulnerabilities across Azure components, with CVE-2026-50481 in Azure Active Directory enabling privilege escalation to access unauthorized data and components.
- Who is affected
- Organizations using Microsoft Azure, particularly those with Azure Active Directory deployments.
- Urgency
- Critical for CVE-2026-50481 (CVSS 9.9); it directly enables privilege escalation in Azure AD and requires immediate action, while other listed CVEs have been centrally patched by Microsoft.
- Action
- Apply Microsoft's fix for CVE-2026-50481 in Azure Active Directory; note that CVE-2026-56162, CVE-2026-50516, CVE-2026-56161, CVE-2026-59115, CVE-2026-62830, CVE-2026-62873, and CVE-2026-68823 are already centrally remediated.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Azure
Get an email when a new Azure advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0287
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-561620.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-505160.77% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 53% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-561610.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-591150.64% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-628300.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-628730.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-688230.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-504810.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-472990.94% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 58% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-656680.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-56162 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50516 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56161 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-59115 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62830 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62873 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-68823 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50481 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-47299 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65668 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62869 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65673 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-63522 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-49163 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70340 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65806 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-57104 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Microsoft Azure and Entra ID: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Microsoft products (August 12, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in Microsoft Azure (August 12, 2026)cert-fr-avis
- highCVE-2026-70340: Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges …nvd
- mediumCVE-2026-65806: Missing authorization in Azure CycleCloud allows an authorized attacker to disclose informatio…nvd
- highCVE-2026-65673: Improper neutralization of special elements used in an sql command ('sql injection') in Micros…nvd
- highCVE-2026-63522: Incorrect permission assignment for critical resource in Azure SQL Database allows an authoriz…nvd
- highCVE-2026-62869: Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker…nvd
- highCVE-2026-57104: Improper neutralization of input during web page generation ('cross-site scripting') in Azure …nvd
- criticalCVE-2026-50516: Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an u…nvd
- highCVE-2026-47299: Improper neutralization of special elements used in a command ('command injection') in Azure M…nvd
- mediumCVE-2026-65806: Azure CycleCloud Information Disclosure Vulnerabilitymsrc
Recent advisories for Microsoft Azure
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Microsoft Azure and Entra ID: Multiple vulnerabilitiescert-bund · 2026-08-12
- unknownMultiple vulnerabilities in Microsoft Azure (August 12, 2026)cert-fr-avis · 2026-08-12
- highCVE-2026-71331: Integer overflow or wraparound in Microsoft Azure Attestation service and Device Health Attest…nvd · 2026-08-11
- highCVE-2026-66802: Concurrent execution using shared resource with improper synchronization ('race condition') in…nvd · 2026-08-11
- criticalCVE-2026-50516: Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an u…nvd · 2026-08-11
- criticalCVE-2026-50516: Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerabilitymsrc · 2026-08-11
More from NCSC-NL Advisories
- unknownNCSC-2026-0302 [1.00] [M/H] Vulnerabilities patched in SAP Commerce Cloud Data Hub Adapter2026-08-15
- unknownNCSC-2026-0301 [1.00] [M/H] Vulnerabilities patched in IBM i operating system by IBM2026-08-14
- unknownNCSC-2026-0300 [1.00] [M/H] Vulnerabilities patched in Fortinet FortiWeb2026-08-13
- unknownNCSC-2026-0299 [1.00] [M/H] Vulnerability patched in Fortinet FortiManager2026-08-13
- unknownNCSC-2026-0298 [1.00] [M/H] Vulnerabilities patched in Autodesk AutoCAD2026-08-13