CVE-2026-58275
An attacker can exploit multiple vulnerabilities in Microsoft Azure, Microsoft 365 Copilot, Microsoft Exchange, and Microsoft Apps Surface to escalate privileges, execute arbitrary code, manipulate data, or disclose confidential information.
CSIRTS triage
- What
- Multiple vulnerabilities can be exploited to escalate privileges, execute arbitrary code, manipulate data, or disclose confidential information.
- Who is affected
- Users of Microsoft Azure, Microsoft 365 Copilot, Microsoft Exchange, and Microsoft Apps Surface.
- Urgency
- Remediation is high urgency due to the severity and potential impact of the vulnerabilities.
- Action
- Update to the latest versions of the affected Microsoft products.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-58275
Get an email if CVE-2026-58275 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.67% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 49% of all EPSS-scored CVEs.
Advisory coverage (3)
- high[NEW] [high] Microsoft Azure, Copilot, Exchange, Surface: Multiple vulnerabilitiescert-bund · 2026-07-27
- criticalCVE-2026-58275: Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over …nvd · 2026-07-24
- criticalCVE-2026-58275: Azure DNS Elevation of Privilege Vulnerabilitymsrc · 2026-07-14
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-58275)