[NEW] [high] Microsoft Azure, Copilot, Exchange, Surface: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Microsoft Azure, Microsoft 365 Copilot, Microsoft Exchange, and Microsoft Apps Surface to escalate privileges, execute arbitrary code, manipulate data, or disclose confidential information.
CSIRTS triage
- What
- Multiple vulnerabilities can be exploited to escalate privileges, execute arbitrary code, manipulate data, or disclose confidential information.
- Who is affected
- Users of Microsoft Azure, Microsoft 365 Copilot, Microsoft Exchange, and Microsoft Apps Surface.
- Urgency
- Remediation is high urgency due to the severity and potential impact of the vulnerabilities.
- Action
- Update to the latest versions of the affected Microsoft products.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Azure, 365 Copilot, Exchange, Apps Surface
Get an email when a new Azure, 365 Copilot, Exchange, Apps Surface advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2502
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-354250.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all scored CVEs.
- Low exploitation riskCVE-2026-491590.55% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all scored CVEs.
- Low exploitation riskCVE-2026-561600.65% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all scored CVEs.
- Low exploitation riskCVE-2026-561630.90% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all scored CVEs.
- Low exploitation riskCVE-2026-561650.72% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all scored CVEs.
- Low exploitation riskCVE-2026-561670.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all scored CVEs.
- Low exploitation riskCVE-2026-571060.90% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all scored CVEs.
- Low exploitation riskCVE-2026-582750.67% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all scored CVEs.
- Low exploitation riskCVE-2026-586300.81% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all scored CVEs.
- Low exploitation riskCVE-2026-628250.70% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-35425 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-49159 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56160 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56163 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56165 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56167 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-57106 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58275 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58630 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62825 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-50517 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56191 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-54120 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- criticalCVE-2026-58630: Improper access control in Azure App Service allows an unauthorized attacker to elevate privil…nvd
- criticalCVE-2026-57106: Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate …nvd
- criticalCVE-2026-56163: Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an u…nvd
- criticalCVE-2026-62825: Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileg…nvd
- criticalCVE-2026-58275: Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over …nvd
- criticalCVE-2026-56191: Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perfor…nvd
- highCVE-2026-56167: Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate…nvd
- criticalCVE-2026-56165: Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute cod…nvd
- criticalCVE-2026-56160: Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to eleva…nvd
- criticalCVE-2026-54120: Improper input validation in Microsoft Surface allows an authorized attacker to execute code o…nvd
- criticalCVE-2026-50517: Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute cod…nvd
- mediumCVE-2026-49159: Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an author…nvd
Recent advisories for Microsoft Azure
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownVulnérabilité dans Microsoft Azure (31 juillet 2026)cert-fr-avis · 2026-07-31
- high[NEW] [high] Microsoft Azure Portal: Vulnerability allows information disclosurecert-bund · 2026-07-28
- criticalCVE-2026-56163: Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an u…nvd · 2026-07-24
- criticalCVE-2025-66390: In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/passw…nvd · 2026-07-21
- unknownCVE-2026-54733: The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Activ…nvd · 2026-07-16
- high[NEW] [high] Microsoft Azure: Multiple vulnerabilitiescert-bund · 2026-07-16
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow unspecified attack2026-07-31