Daily advisories covering CVEs and security issues affecting Microsoft Azure and its underlying components: Entra ID (formerly AAD), Microsoft Defender for Cloud, Azure Kubernetes Service, Azure Linux kernel vulnerabilities, and the wider Azure service portfolio. Each advisory includes severity, attack vector, and a recommended action for architects managing Azure workloads.

Looking for deeper context on cross-cloud security controls? Our practitioner guides cover the principles that apply across AWS, Azure, and GCP:

CVE-2026-35425: Azure APIM RCE Vulnerability

CVE-2026-35425 is a remote code execution flaw in Azure API Management caused by improper access controls. Learn the impact and mitigation steps.

🔴 Critical  |  Microsoft Security Response Center  |  23 Jul 2026

CVE-2026-50517: M365 Copilot RCE Vulnerability

CVE-2026-50517 is a remote code execution flaw in Microsoft 365 Copilot caused by unsafe deserialization. Patch immediately to protect enterprise data.

🔴 Critical  |  Microsoft Security Response Center  |  23 Jul 2026

CVE-2026-56163: Azure Kubernetes Service Privilege Escalatio

CVE-2026-56163 lets unauthenticated attackers escalate privileges in Azure Kubernetes Service over a network. Learn the impact and how to respond.

🔴 Critical  |  Microsoft Security Response Center  |  23 Jul 2026

CVE-2026-56165: Microsoft Account RCE Vulnerability

CVE-2026-56165 is a critical heap buffer overflow in Microsoft Account enabling unauthenticated remote code execution. Patch immediately.

🔴 Critical  |  Microsoft Security Response Center  |  23 Jul 2026

CVE-2026-62825: Azure Key Vault Privilege Escalation

CVE-2026-62825 allows unauthenticated attackers to elevate privileges in Azure Key Vault via improper authentication. Learn the security impact and mitigat

🔴 Critical  |  Microsoft Security Response Center  |  23 Jul 2026

CVE-2026-59117 Windows Terminal RCE Vulnerability

CVE-2026-59117 is a critical Windows Terminal RCE flaw allowing unauthenticated network attackers to execute code. Patch immediately to protect Azure envir

🔴 Critical  |  Microsoft Security Response Center  |  16 Jul 2026

CVE-2026-42990: SQL Server ODBC Driver RCE Flaw

CVE-2026-42990 is a critical heap buffer overflow in the SQL Server ODBC driver enabling unauthenticated remote code execution. Patch immediately.

🔴 Critical  |  Microsoft Security Response Center  |  14 Jul 2026

CVE-2026-48561: Microsoft Copilot RCE Vulnerability

CVE-2026-48561 is a critical command injection flaw in Microsoft Copilot allowing unauthenticated remote code execution. Learn the security impact and reme

🔴 Critical  |  Microsoft Security Response Center  |  14 Jul 2026

CVE-2026-49164: AD Domain Services RCE Flaw

CVE-2026-49164 is a critical unauthenticated RCE vulnerability in Windows Active Directory Domain Services via a heap buffer overflow. Patch immediately.

🔴 Critical  |  Microsoft Security Response Center  |  14 Jul 2026

CVE-2026-10536: Azure HTTP/2 UAF Vulnerability

CVE-2026-10536 is a Use-After-Free flaw in HTTP/2 stream-dependency handling affecting Azure. Learn the impact and how to mitigate it.

🔴 Critical  |  Microsoft Security Response Center  |  7 Jul 2026

CVE-2026-56645: Microsoft Edge RCE Vulnerability

CVE-2026-56645 is a critical heap buffer overflow in Microsoft Edge allowing unauthenticated remote code execution. Patch immediately.

🔴 Critical  |  Microsoft Security Response Center  |  3 Jul 2026

CVE-2026-57975: Microsoft Edge RCE Vulnerability

CVE-2026-57975 is a type confusion RCE flaw in Microsoft Edge (Chromium-based) allowing unauthenticated remote code execution. Patch immediately.

🔴 Critical  |  Microsoft Security Response Center  |  3 Jul 2026

CVE-2026-57984: Microsoft Edge RCE Vulnerability

CVE-2026-57984 is a use-after-free flaw in Microsoft Edge allowing remote code execution over a network. Patch immediately to protect endpoints.

🔴 Critical  |  Microsoft Security Response Center  |  3 Jul 2026

CVE-2026-57988: Microsoft Edge RCE Vulnerability

CVE-2026-57988 is a critical RCE flaw in Microsoft Edge via path traversal. Learn the impact and how to protect your cloud environment.

🔴 Critical  |  Microsoft Security Response Center  |  3 Jul 2026

CVE-2026-57992: Microsoft Edge RCE Vulnerability

CVE-2026-57992 is a critical use-after-free RCE flaw in Microsoft Edge (Chromium-based). Patch immediately to prevent remote code execution attacks.

🔴 Critical  |  Microsoft Security Response Center  |  3 Jul 2026

CVE-2026-48914: QEMU-KVM Heap Overflow in Azure

CVE-2026-48914 is a heap buffer overflow in QEMU-KVM's virtio-blk SCSI handling, risking VM escape on Azure and self-managed KVM hosts.

🔴 Critical  |  Microsoft Security Response Center  |  19 Jun 2026

CVE-2026-45480: Azure Active Directory Privilege Escalation

CVE-2026-45480 is an Azure Active Directory elevation of privilege flaw allowing unauthenticated attackers to escalate privileges over a network. Patch urg

🔴 Critical  |  Microsoft Security Response Center  |  18 Jun 2026

CVE-2026-16807: Chromium Codecs Out-of-Bounds Write

CVE-2026-16807 is an out-of-bounds write flaw in Chromium Codecs affecting Microsoft Edge. Learn the security impact and how to patch.

🟠 High  |  Microsoft Security Response Center  |  25 Jul 2025

CVE-2026-16806: Use-After-Free in Edge WebMCP

CVE-2026-16806 is a use-after-free flaw in Chromium's WebMCP affecting Microsoft Edge. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  25 Jul 2025

CVE-2026-16805: Use After Free in Blink – Edge Risk

CVE-2026-16805 is a use-after-free flaw in Chromium's Blink engine affecting Microsoft Edge. Update Edge immediately to mitigate potential code execution.

🟠 High  |  Microsoft Security Response Center  |  25 Jul 2025

CVE-2026-16804: Use-After-Free in Microsoft Edge Chromium

CVE-2026-16804 is a use-after-free flaw in Chromium's Input component affecting Microsoft Edge. Learn the risk and recommended patching steps.

🟠 High  |  Microsoft Security Response Center  |  25 Jul 2025

CVE-2026-64600: Azure Linux XFS Kernel Vulnerability

CVE-2026-64600 affects the Linux XFS filesystem driver. Azure VM and container workloads may be at risk. Patch Linux kernels promptly to mitigate exposure.

🟠 High  |  Microsoft Security Response Center  |  24 Jul 2025

CVE-2026-59677: Process Kill Flaw in seunshare | Azure

CVE-2026-59677 exposes a process kill attack vector in seunshare's killall() function, posing a risk to Azure Linux workloads using SELinux-based sandboxin

🟠 High  |  Microsoft Security Response Center  |  24 Jul 2025

CVE-2026-59676: seunshare rm_rf() File Deletion Flaw

CVE-2026-59676 exposes a local file deletion attack vector in seunshare's rm_rf() function, posing risks to Azure Linux workloads. Learn what to do.

🟠 High  |  Microsoft Security Response Center  |  24 Jul 2025

CVE-2026-49159: Microsoft Graph Info Disclosure Flaw

CVE-2026-49159 exposes sensitive data via Microsoft Graph to authenticated attackers over a network. Learn the impact and how to protect your environment.

🟠 High  |  Microsoft Security Response Center  |  23 Jul 2025

CVE-2026-54120 Microsoft Surface RCE Vulnerability

CVE-2026-54120 allows authorised attackers to execute code remotely on Microsoft Surface devices via improper input validation. Patch now.

🟠 High  |  Microsoft Security Response Center  |  23 Jul 2025

CVE-2026-56160: Azure Red Hat OpenShift Privilege Escalation

CVE-2026-56160 allows authorised attackers to escalate privileges in Azure Red Hat OpenShift (ARO) via improper authorisation controls. Patch now.

🟠 High  |  Microsoft Security Response Center  |  23 Jul 2025

CVE-2026-56167: Azure AI Search Privilege Escalation

CVE-2026-56167 is an SSRF flaw in Azure AI Search allowing authorised attackers to escalate privileges over a network. Learn what action to take.

🟠 High  |  Microsoft Security Response Center  |  23 Jul 2025

CVE-2026-56191: Exchange Online Tampering Flaw

CVE-2026-56191 affects Microsoft Exchange Online, allowing unauthenticated attackers to tamper with data over a network. Learn the security impact and miti

🟠 High  |  Microsoft Security Response Center  |  23 Jul 2025

CVE-2026-57106 Azure Data Quality SSRF Privilege Escalation

CVE-2026-57106 is an SSRF flaw in Azure Data Quality enabling unauthenticated privilege escalation over a network. Patch and review exposure now.

🟠 High  |  Microsoft Security Response Center  |  23 Jul 2025

CVE-2026-58275: Azure DNS Privilege Escalation Flaw

CVE-2026-58275 is an Azure DNS elevation of privilege vulnerability allowing unauthenticated network attackers to escalate privileges. Learn the security i

🟠 High  |  Microsoft Security Response Center  |  23 Jul 2025

CVE-2026-58630: Azure App Service Privilege Escalation

CVE-2026-58630 affects Azure App Service on Azure Stack Hub, allowing unauthenticated network attackers to elevate privileges. Patch and mitigate now.

🟠 High  |  Microsoft Security Response Center  |  23 Jul 2025

CVE-2026-62835: Azure Online Services Info Disclosure

CVE-2026-62835 is an improper authorisation flaw in Microsoft Online Services allowing unauthenticated remote attackers to disclose sensitive information.

🟠 High  |  Microsoft Security Response Center  |  23 Jul 2025

CVE-2026-55973: Azure DNS Stack Buffer Overflow Flaw

CVE-2026-55973 exposes a stack buffer overflow via DNS error reporting config in Azure. Learn the risk and how to protect your infrastructure.

🟠 High  |  Microsoft Security Response Center  |  23 Jul 2025

CVE-2026-53910: GNU diffutils Buffer Overflow in Azure

CVE-2026-53910 is a heap-based buffer overflow in GNU diffutils affecting Azure environments. Learn the risk and how to remediate.

🟠 High  |  Microsoft Security Response Center  |  23 Jul 2025

CVE-2026-63136: Elasticsearch DoS on Azure

CVE-2026-63136 enables uncontrolled resource consumption in Elasticsearch on Azure, leading to Denial of Service. Patch and restrict access now.

🟠 High  |  Microsoft Security Response Center  |  23 Jul 2025

CVE-2026-63140: Elasticsearch DoS Flaw on Azure

CVE-2026-63140 is a reachable assertion bug in Elasticsearch that can cause denial of service in Azure environments. Learn what architects should do now.

🟠 High  |  Microsoft Security Response Center  |  23 Jul 2025

CVE-2026-56145: Elasticsearch DoS Flaw on Azure

CVE-2026-56145 is an uncontrolled resource consumption flaw in Elasticsearch that can cause Denial of Service in Azure environments. Patch now.

🟠 High  |  Microsoft Security Response Center  |  23 Jul 2025

CVE-2026-56434: NGINX SSI Module Flaw on Azure

CVE-2026-56434 affects NGINX's ngx_http_ssi_module. Azure users running NGINX workloads should review exposure and apply patches promptly.

🟠 High  |  Microsoft Security Response Center  |  22 Jul 2025

CVE-2026-42533: NGINX Map & Regex Vulnerability on Azure

CVE-2026-42533 affects NGINX Map directive regex matching on Azure. Learn the impact, risks, and steps cloud architects should take to remediate.

🟠 High  |  Microsoft Security Response Center  |  22 Jul 2025

CVE-2026-59885: pyasn1 DoS Flaw Affects Azure

CVE-2026-59885 exposes a denial-of-service risk in pyasn1 via quadratic complexity in OID parsing. Azure workloads using pyasn1 should patch promptly.

🟠 High  |  Microsoft Security Response Center  |  22 Jul 2025

CVE-2026-57215: RabbitMQ Reply Channel Injection Flaw

CVE-2026-57215 exposes RabbitMQ to unauthorised reply-channel injection via persistent direct-reply-to bindings, risking message interception on Azure.

🟠 High  |  Microsoft Security Response Center  |  22 Jul 2025

CVE-2026-57211: RabbitMQ SSRF Flaw on Windows Azure

CVE-2026-57211 is an SSRF vulnerability in RabbitMQ's management UI on Windows, posing credential theft and internal network exposure risks in Azure enviro

🟠 High  |  Microsoft Security Response Center  |  22 Jul 2025

CVE-2026-57216: RabbitMQ Guest Session Bypass

CVE-2026-57216 allows remote guest sessions in RabbitMQ by bypassing loopback enforcement in AMQP 1.0, AMQP 0-9-1, and Stream protocols. Patch now.

🟠 High  |  Microsoft Security Response Center  |  22 Jul 2025

CVE-2026-57213: RabbitMQ Stored XSS Federation Plugin

CVE-2026-57213 exposes a stored XSS flaw in RabbitMQ's federation management plugin via unsanitised consumer_tag rendering. Learn the risks and mitigations

🟠 High  |  Microsoft Security Response Center  |  22 Jul 2025

CVE-2026-57217: RabbitMQ Topic Auth Bypass on Azure

CVE-2026-57217 allows cross-tenant routing-key bypass in RabbitMQ topic authorisation, risking message interception in multi-tenant Azure deployments.

🟠 High  |  Microsoft Security Response Center  |  22 Jul 2025

CVE-2026-57220: RabbitMQ DoS via Frame-Size Bypass

CVE-2026-57220 allows unauthenticated attackers to exhaust RabbitMQ server memory by bypassing stream frame-size limits. Patch or restrict access now.

🟠 High  |  Microsoft Security Response Center  |  22 Jul 2025

CVE-2026-64188: Azure Linux Kernel Use-After-Free Flaw

CVE-2026-64188 is a Linux kernel use-after-free vulnerability in the Qualcomm RmNet driver affecting Azure workloads. Patch now.

🟠 High  |  Microsoft Security Response Center  |  22 Jul 2025

CVE-2026-64189: Azure Linux Kernel netfilter Race Condition

CVE-2026-64189 is a Linux kernel netfilter ipset race condition affecting Azure Linux workloads. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  22 Jul 2025

CVE-2026-64192: Azure Linux BPF LSM Security Flaw

CVE-2026-64192 patches a Linux kernel BPF LSM initialisation flaw affecting Azure workloads. Learn the risk and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  22 Jul 2025

CVE-2026-26199: HDF5 Buffer Underflow in Azure

CVE-2026-26199 is a buffer underflow flaw in HDF5 H5Iget_name/H5G_get_name affecting Azure. Learn what cloud architects need to do.

🟠 High  |  Microsoft Security Response Center  |  22 Jul 2025

CVE-2026-26197: Azure HDF5 Array Validation Flaw

CVE-2026-26197 exposes an array size validation flaw in H5Odtype.c, risking memory corruption in Azure workloads that process HDF5 files. Patch promptly.

🟠 High  |  Microsoft Security Response Center  |  22 Jul 2025

CVE-2026-50462 WinSock EoP Vulnerability | Azure Windows

CVE-2026-50462 is a Windows WinSock elevation of privilege flaw. Learn what cloud architects need to know and what action to take.

🟠 High  |  Microsoft Security Response Center  |  21 Jul 2025

CVE-2026-58640 Windows NTFS RCE Vulnerability

CVE-2026-58640 is a Windows NTFS Remote Code Execution flaw. Latest update is an acknowledgement change only — no new patches issued.

🟠 High  |  Microsoft Security Response Center  |  21 Jul 2025

CVE-2026-63796: Azure ocfs2 Bitmap Descriptor Flaw

CVE-2026-63796 affects the ocfs2 Linux cluster file system, allowing oversized bitmap descriptors that could destabilise or compromise Azure Linux VMs.

🟠 High  |  Microsoft Security Response Center  |  21 Jul 2025

CVE-2026-3842: QEMU-KVM Hyper-V OOB Write Flaw

CVE-2026-3842 exposes a host out-of-bounds write in QEMU-KVM's Hyper-V SynDbg. Learn the risk and how to protect your Azure and KVM environments.

🟠 High  |  Microsoft Security Response Center  |  21 Jul 2025

CVE-2026-63801: Linux TIPC Kernel Flaw on Azure

CVE-2026-63801 is a Linux kernel use-after-free bug in TIPC decryption affecting Azure Linux workloads. Learn the risk and mitigation steps.

🟠 High  |  Microsoft Security Response Center  |  21 Jul 2025

CVE-2026-64017: Azure Linux Kernel blk-mq Flaw

CVE-2026-64017 affects the Linux kernel blk-mq subsystem in Azure environments. Learn the security impact and what architects should do now.

🟠 High  |  Microsoft Security Response Center  |  21 Jul 2025

CVE-2026-63879: Azure Linux AMDGPU Kernel Flaw

CVE-2026-63879 affects the Linux kernel AMDGPU driver on Azure GPU VMs. Learn the impact and patching steps for cloud security teams.

🟠 High  |  Microsoft Security Response Center  |  21 Jul 2025

CVE-2026-64077: Azure Linux Kernel netfilter Flaw

CVE-2026-64077 affects the Linux kernel netfilter ebtables subsystem on Azure VMs. Learn what cloud architects should do to mitigate risk.

🟠 High  |  Microsoft Security Response Center  |  21 Jul 2025

CVE-2024-35248 Dynamics 365 Business Central EoP

CVE-2024-35248 is an elevation of privilege flaw in Microsoft Dynamics 365 Business Central. Build numbers updated — check your patch status now.

🟠 High  |  Microsoft Security Response Center  |  20 Jul 2025

CVE-2026-47304: .NET Security Feature Bypass Vulnerability

Microsoft updates CVE-2026-47304 advisory for a .NET security feature bypass. Review patching scope for Azure and on-prem .NET workloads.

🟠 High  |  Microsoft Security Response Center  |  20 Jul 2025

CVE-2026-50525: .NET Denial of Service Vulnerability

CVE-2026-50525 is a .NET Denial of Service vulnerability. Learn the impact on Azure workloads and what cloud architects should do to mitigate risk.

🟠 High  |  Microsoft Security Response Center  |  20 Jul 2025

CVE-2026-50646: .NET Framework RCE Vulnerability

Microsoft updates product info for CVE-2026-50646, a .NET Framework RCE flaw. Learn what Azure architects need to know and action.

🟠 High  |  Microsoft Security Response Center  |  20 Jul 2025

CVE-2026-50648: .NET Framework DoS Vulnerability

Microsoft updates CVE-2026-50648 advisory for a .NET Framework Denial of Service flaw. Review revised product scope and ensure patches are applied across a

🟠 High  |  Microsoft Security Response Center  |  20 Jul 2025

CVE-2026-50649: .NET Remote Code Execution Flaw

CVE-2026-50649 is a .NET remote code execution vulnerability. Review Microsoft's updated advisory and patch affected runtimes across Azure workloads.

🟠 High  |  Microsoft Security Response Center  |  20 Jul 2025

CVE-2026-50650 .NET Framework Privilege Escalation

CVE-2026-50650 is a .NET Framework elevation of privilege vulnerability. Learn what it means for Azure workloads and how to remediate it.

🟠 High  |  Microsoft Security Response Center  |  20 Jul 2025

CVE-2026-63815: Azure Linux f2fs Kernel Vulnerability

CVE-2026-63815 affects the Linux f2fs kernel driver on Azure. Learn the impact on Azure VMs and containers, and what architects should do now.

🟠 High  |  Microsoft Security Response Center  |  20 Jul 2025

CVE-2026-50012: Squid Memory Corruption Vulnerability

CVE-2026-50012 is a memory corruption flaw in Squid's cache digest reply handling. Azure deployments using Squid proxies should patch immediately.

🟠 High  |  Microsoft Security Response Center  |  18 Jul 2025

CVE-2026-47729: Squid FTP Gateway Memory Disclosure

CVE-2026-47729 exposes a memory disclosure flaw in Squid's FTP gateway. Azure users running Squid should patch immediately to prevent sensitive data leakag

🟠 High  |  Microsoft Security Response Center  |  18 Jul 2025

CVE-2026-62299 CoreDNS Rewrite Plugin Remote DoS

CVE-2026-62299 exposes a nil-pointer panic in CoreDNS's rewrite plugin, enabling remote denial-of-service attacks on Kubernetes and Azure workloads.

🟠 High  |  Microsoft Security Response Center  |  18 Jul 2025

CVE-2026-62309: CoreDNS Remote DoS via PPv2 Packet

CVE-2026-62309 allows a remote attacker to crash CoreDNS with a single 28-byte packet, risking DNS outages in Kubernetes and Azure environments.

🟠 High  |  Microsoft Security Response Center  |  18 Jul 2025

CVE-2026-15905: Use-After-Free in Edge Chromium Aura

CVE-2026-15905 is a use-after-free flaw in Chromium's Aura framework affecting Microsoft Edge. Learn the security impact and patching steps.

🟠 High  |  Microsoft Security Response Center  |  18 Jul 2025

CVE-2026-15904 Use After Free in Chromium Ozone | Edge

CVE-2026-15904 is a use-after-free flaw in Chromium's Ozone layer affecting Microsoft Edge. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  18 Jul 2025

CVE-2026-15903: Edge Chromium V8 Out-of-Bounds Flaw

CVE-2026-15903 is an out-of-bounds read/write flaw in the V8 JavaScript engine affecting Microsoft Edge. Update immediately to mitigate code execution risk

🟠 High  |  Microsoft Security Response Center  |  18 Jul 2025

CVE-2026-15902: Use-After-Free in Edge Cast

CVE-2026-15902 is a use-after-free flaw in Chromium's Cast component affecting Microsoft Edge. Update Edge immediately to mitigate potential code execution

🟠 High  |  Microsoft Security Response Center  |  18 Jul 2025

CVE-2026-15901: Chromium Use-After-Free in Edge

CVE-2026-15901 is a use-after-free flaw in Chromium's Network component affecting Microsoft Edge. Learn the security impact and patching steps.

🟠 High  |  Microsoft Security Response Center  |  18 Jul 2025

CVE-2026-15900: Chromium GPU Use-After-Free in Edge

CVE-2026-15900 is a use-after-free flaw in Chromium's GPU component affecting Microsoft Edge. Update Edge immediately to mitigate potential code execution

🟠 High  |  Microsoft Security Response Center  |  18 Jul 2025

CVE-2026-15899: Use After Free in Edge CameraCapture

CVE-2026-15899 is a use-after-free flaw in Chromium's CameraCapture component affecting Microsoft Edge. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  18 Jul 2025

CVE-2026-56159: DHCP Server RCE Vulnerability (Azure)

CVE-2026-56159 is a Remote Code Execution flaw in Windows DHCP Server Service. Learn what cloud security architects need to know and do.

🟠 High  |  Microsoft Security Response Center  |  17 Jul 2025

CVE-2026-59884: pyasn1 Denial of Service on Azure

CVE-2026-59884 exposes a denial-of-service flaw in pyasn1's ASN.1 decoder. Azure workloads using Python should patch immediately to prevent service disrupt

🟠 High  |  Microsoft Security Response Center  |  17 Jul 2025

CVE-2026-60081: DBI::ProfileData Perl Path Index Flaw

CVE-2026-60081 exposes a path index limitation flaw in DBI::ProfileData for Perl before v1.651. Learn the security impact and how to remediate.

🟠 High  |  Microsoft Security Response Center  |  17 Jul 2025

CVE-2026-60082: Perl DBI Vulnerability Fixed in v1.651

CVE-2026-60082 affects Perl DBI versions before 1.651, failing to enforce statement handle consistency. Learn the impact and how to remediate on Azure.

🟠 High  |  Microsoft Security Response Center  |  17 Jul 2025

CVE-2026-57433: Perl Storable Integer Overflow Fix

CVE-2026-57433 affects Perl Storable before 3.41, causing a signed integer overflow during deserialisation. Upgrade now to protect Azure workloads.

🟠 High  |  Microsoft Security Response Center  |  17 Jul 2025

CVE-2026-15709: libsoup WebSocket DoS Flaw on Azure

CVE-2026-15709 exposes a denial-of-service risk in libsoup's WebSocket permessage-deflate handling. Learn the impact and mitigation steps for Azure workloa

🟠 High  |  Microsoft Security Response Center  |  17 Jul 2025

CVE-2026-15712: libsoup3 HTTP/2 Heap Buffer Over-Read

CVE-2026-15712 exposes a heap buffer over-read in libsoup3's HTTP/2 GOAWAY frame parsing, risking memory disclosure on Azure workloads.

🟠 High  |  Microsoft Security Response Center  |  17 Jul 2025

CVE-2026-15714: Libsoup Out-of-Bounds Read on Azure

CVE-2026-15714 is an out-of-bounds read in libsoup's multipart input stream. Learn the impact on Azure workloads and how to remediate.

🟠 High  |  Microsoft Security Response Center  |  17 Jul 2025

CVE-2026-15713: libsoup HTTP/2 DoS Vulnerability on Azure

CVE-2026-15713 allows remote attackers to cause a denial of service via a memory leak in libsoup's HTTP/2 frame window handling. Azure workloads at risk.

🟠 High  |  Microsoft Security Response Center  |  17 Jul 2025

CVE-2026-15711: libsoup WebSocket DoS on Azure

CVE-2026-15711 is a libsoup WebSocket denial-of-service flaw affecting Azure Linux workloads. Learn the risks and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  17 Jul 2025

CVE-2026-53366: Azure Linux Kernel IPv4 Flaw

CVE-2026-53366 targets a Linux kernel IPv4 memory allocation flaw affecting Azure workloads. Learn the impact and recommended mitigations.

🟠 High  |  Microsoft Security Response Center  |  17 Jul 2025

CVE-2026-48863: Libsolv Buffer Overflow on Azure

CVE-2026-48863 is a stack-based buffer overflow in libsolv's EdDSA PGP verification, enabling denial of service on Azure and Linux workloads.

🟠 High  |  Microsoft Security Response Center  |  17 Jul 2025

CVE-2026-50304: AD FS Denial of Service Vulnerability

CVE-2026-50304 affects Windows AD FS, enabling denial of service attacks that could disrupt authentication in hybrid Azure environments. Patch now.

🟠 High  |  Microsoft Security Response Center  |  16 Jul 2025

CVE-2026-50324: AD FS Denial of Service Vulnerability

CVE-2026-50324 affects Windows AD FS with a denial of service risk. Learn what cloud security architects need to know and do.

🟠 High  |  Microsoft Security Response Center  |  16 Jul 2025

CVE-2026-50355: AD FS Denial of Service Vulnerability

CVE-2026-50355 affects Windows AD FS with a Denial of Service risk. Updated product info released. Find out what Azure architects need to know.

🟠 High  |  Microsoft Security Response Center  |  16 Jul 2025

CVE-2026-50368: AD FS Denial of Service Vulnerability

CVE-2026-50368 affects Windows AD FS, enabling denial of service attacks that could disrupt authentication in hybrid Azure environments. Patch now.

🟠 High  |  Microsoft Security Response Center  |  16 Jul 2025

CVE-2026-50411: Windows AD FS DoS Vulnerability

CVE-2026-50411 is a Denial of Service flaw in Windows AD FS that could disrupt federated authentication. Review Microsoft's updated advisory and patch prom

🟠 High  |  Microsoft Security Response Center  |  16 Jul 2025

CVE-2026-50647: AD FS Denial of Service Vulnerability

CVE-2026-50647 is a Denial of Service flaw in Active Directory Federation Services. Learn the impact and patching guidance for cloud security teams.

🟠 High  |  Microsoft Security Response Center  |  16 Jul 2025

CVE-2026-50652: Azure Active Directory DoS Vulnerability

CVE-2026-50652 is a Denial of Service flaw in Azure Active Directory that could disrupt authentication. Learn what architects should do now.

🟠 High  |  Microsoft Security Response Center  |  16 Jul 2025

CVE-2026-50653: Azure Active Directory DoS Vulnerability

CVE-2026-50653 is a Denial of Service flaw in Azure Active Directory that could disrupt authentication services. Learn what cloud architects should do.

🟠 High  |  Microsoft Security Response Center  |  16 Jul 2025

CVE-2026-56171: Windows RDP Info Disclosure Flaw

CVE-2026-56171 is a Windows RDP information disclosure vulnerability allowing unauthenticated network attackers to expose private data. Patch now.

🟠 High  |  Microsoft Security Response Center  |  16 Jul 2025

CVE-2026-58598 Windows Backup Service Privilege Escalation

CVE-2026-58598 is a race condition in Windows Backup Service allowing local privilege escalation. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  16 Jul 2025

CVE-2026-58643: Windows Admin Center XSS Spoofing Flaw

CVE-2026-58643 is an XSS spoofing vulnerability in Windows Admin Center allowing unauthenticated network attackers to compromise admin sessions. Patch now.

🟠 High  |  Microsoft Security Response Center  |  16 Jul 2025

CVE-2026-59831: GitHub CLI Codespace RCE Flaw

CVE-2026-59831 allows remote code execution via GitHub CLI's gh codespace jupyter command when connecting to a malicious Codespace. Patch promptly.

🟠 High  |  Microsoft Security Response Center  |  16 Jul 2025

CVE-2026-50375: DirectX Graphics Kernel EoP Vulnerability

CVE-2026-50375 is a Windows DirectX Graphics Kernel elevation of privilege flaw. This update is an informational acknowledgment change only — no new patche

🟠 High  |  Microsoft Security Response Center  |  15 Jul 2025

CVE-2026-56182 Windows NTFS Privilege Escalation

CVE-2026-56182 is a Windows NTFS elevation of privilege flaw affecting Azure VMs and Windows workloads. Latest update is an acknowledgment change only.

🟠 High  |  Microsoft Security Response Center  |  15 Jul 2025

CVE-2026-58644 SharePoint RCE Advisory Corrected

Microsoft corrects the CVSS vector, exploitability rating, and exploitation status for CVE-2026-58644, a SharePoint Remote Code Execution vulnerability.

🟠 High  |  Microsoft Security Response Center  |  15 Jul 2025

CVE-2026-58253: NATS Server Route API Auth Bypass

CVE-2026-58253 exposes a NATS Server authentication bypass in the Route API, risking unauthorised cluster access in Azure cloud-native environments.

🟠 High  |  Microsoft Security Response Center  |  15 Jul 2025

CVE-2026-58209: NATS Server MQTT Filter Bypass

CVE-2026-58209 allows MQTT retained and QoS replay to bypass subscription deny filters in NATS Server, risking unauthorised message access.

🟠 High  |  Microsoft Security Response Center  |  15 Jul 2025

CVE-2026-58252: NATS Server Auth Bypass via Wildcard

CVE-2026-58252 allows attackers to bypass NATS Server subscription authorisation using wildcard overlaps, risking unauthorised message access in cloud-nati

🟠 High  |  Microsoft Security Response Center  |  15 Jul 2025

CVE-2026-58250: NATS Server Pre-Auth Crash via Leafnode

CVE-2026-58250 allows unauthenticated attackers to crash NATS Server via a malformed leafnode handshake. Patch immediately to prevent denial of service.

🟠 High  |  Microsoft Security Response Center  |  15 Jul 2025

CVE-2026-58208: NATS Server WebSocket Crash Flaw

CVE-2026-58208 lets attackers crash NATS JetStream servers via MQTT-over-WebSocket, even without MQTT enabled. Patch now to prevent DoS.

🟠 High  |  Microsoft Security Response Center  |  15 Jul 2025

CVE-2026-58251: NATS Server Queue Subscribe Auth Bypass

CVE-2026-58251 exposes a queue subscribe authorisation bypass in NATS Server, risking unauthorised message access on Azure-hosted workloads.

🟠 High  |  Microsoft Security Response Center  |  15 Jul 2025

CVE-2026-58207: NATS Server Remote Crash via Integer Overflo

CVE-2026-58207 allows remote attackers to crash NATS Server via an integer overflow in Connz pagination, risking denial of service in cloud-native environm

🟠 High  |  Microsoft Security Response Center  |  15 Jul 2025

CVE-2026-57219: RabbitMQ OAuth Credential Leak via API

CVE-2026-57219 exposes OAuth 2.0 client credentials in RabbitMQ via an unauthenticated HTTP API endpoint under certain configurations. Learn the risk and m

🟠 High  |  Microsoft Security Response Center  |  15 Jul 2025

CVE-2026-15028: Libarchive Heap Overflow in Azure

CVE-2026-15028 is a libarchive heap overflow triggered by malformed TAR PAX headers, affecting Azure workloads. Learn the security impact and mitigation st

🟠 High  |  Microsoft Security Response Center  |  15 Jul 2025

CVE-2026-39822: Root Escape via Symlink in Azure

CVE-2026-39822 enables root directory escape via symlink and trailing slash path manipulation. Learn the Azure security impact and mitigation steps.

🟠 High  |  Microsoft Security Response Center  |  15 Jul 2025

CVE-2026-57432: Perl Integer Overflow Heap Read Risk

CVE-2026-57432 affects Perl up to 5.43.10, causing an integer overflow and heap out-of-bounds read in pack/unpack. Azure workloads using Perl are at risk.

🟠 High  |  Microsoft Security Response Center  |  15 Jul 2025

CVE-2026-42900: Windows App Store Privilege Escalation

CVE-2026-42900 is a race condition flaw in Windows App Store enabling remote privilege escalation. Learn the risks and recommended mitigations.

🟠 High  |  Microsoft Security Response Center  |  14 Jul 2025

CVE-2026-42975: Windows Bluetooth RCE Vulnerability

CVE-2026-42975 is a heap buffer overflow in the Windows Bluetooth Port Driver enabling unauthenticated remote code execution over adjacent networks.

🟠 High  |  Microsoft Security Response Center  |  14 Jul 2025

CVE-2026-42982: Windows Secure Kernel Mode EoP Flaw

CVE-2026-42982 allows local privilege escalation via a flaw in Windows Secure Kernel Mode. Azure VM and VDI environments should patch immediately.

🟠 High  |  Microsoft Security Response Center  |  14 Jul 2025

CVE-2026-47296: SQL Server Privilege Escalation Fix

CVE-2026-47296 is a SQL injection flaw in Microsoft SQL Server enabling local privilege escalation. Patch immediately to protect Azure and on-prem deployme

🟠 High  |  Microsoft Security Response Center  |  14 Jul 2025

CVE-2026-47300: ASP.NET Core Privilege Escalation

CVE-2026-47300 is an ASP.NET Core elevation of privilege flaw caused by a faulty authentication implementation, allowing attackers to escalate access over

🟠 High  |  Microsoft Security Response Center  |  14 Jul 2025

CVE-2026-47302: .NET Denial of Service Vulnerability

CVE-2026-47302 allows unauthenticated attackers to deny service via unbounded resource allocation in .NET. Learn the impact and mitigation steps.

🟠 High  |  Microsoft Security Response Center  |  14 Jul 2025

CVE-2026-47303: ASP.NET Core Privilege Escalation

CVE-2026-47303 is an ASP.NET Core elevation of privilege flaw allowing authenticated attackers to escalate permissions over a network. Patch now.

🟠 High  |  Microsoft Security Response Center  |  14 Jul 2025

CVE-2026-48571: Windows App Installer Privilege Escalation

CVE-2026-48571 is a use-after-free flaw in Windows App Package Installer allowing local privilege escalation. Patch Azure Windows VMs immediately.

🟠 High  |  Microsoft Security Response Center  |  14 Jul 2025

CVE-2026-48572: Windows App Installer Privilege Escalation

CVE-2026-48572 is a race condition flaw in Windows App Installer allowing local privilege escalation. Learn what cloud architects should do now.

🟠 High  |  Microsoft Security Response Center  |  14 Jul 2025

CVE-2026-49162: Microsoft Brokering File System EoP

CVE-2026-49162 is a use-after-free vulnerability in Microsoft Brokering File System enabling local privilege escalation. Patch Windows hosts promptly.

🟠 High  |  Microsoft Security Response Center  |  14 Jul 2025

CVE-2026-49166: Windows Print Driver Privilege Escalation

CVE-2026-49166 is a use-after-free flaw in Windows printer drivers enabling local privilege escalation. Patch Azure VMs and Windows endpoints urgently.

🟠 High  |  Microsoft Security Response Center  |  14 Jul 2025

CVE-2026-49167: Windows Kernel Privilege Escalation

CVE-2026-49167 is a Windows Kernel use-after-free flaw enabling local privilege escalation. Azure VM and hybrid workloads are at risk — patch promptly.

🟠 High  |  Microsoft Security Response Center  |  14 Jul 2025

CVE-2026-49168: Storage Spaces Direct Privilege Escalation

CVE-2026-49168 is an integer overflow flaw in Windows Storage Spaces Direct allowing privilege escalation via physical attack. Patch Windows Server and Azu

🟠 High  |  Microsoft Security Response Center  |  14 Jul 2025

CVE-2026-49169 Windows DNS Server RCE Vulnerability

CVE-2026-49169 is a use-after-free flaw in Windows DNS Server enabling authenticated remote code execution. Patch immediately to protect critical infrastru

🟠 High  |  Microsoft Security Response Center  |  14 Jul 2025

CVE-2022-4543 EntryBleed: Linux KASLR Leak on Azure

CVE-2022-4543 'EntryBleed' lets local attackers bypass Linux KASLR via TLB timing on Intel systems. Learn the impact for Azure Linux workloads.

🟠 High  |  Microsoft Security Response Center  |  13 Jul 2025

CVE-2026-59874: node-tar Infinite Loop DoS Flaw

CVE-2026-59874 in node-tar allows a negative tar entry size to trigger an infinite loop. Learn the impact and how to protect Azure workloads.

🟠 High  |  Microsoft Security Response Center  |  12 Jul 2025

CVE-2026-59873: node-tar DoS Flaw Affects Azure Workloads

CVE-2026-59873 is a denial-of-service bug in node-tar allowing malicious archives to exhaust resources. Azure Node.js workloads should patch immediately.

🟠 High  |  Microsoft Security Response Center  |  12 Jul 2025

CVE-2026-59871: node-tar PAX Path Crash on Azure

CVE-2026-59871 affects node-tar, causing process crashes via PAX numeric path type confusion. Azure workloads using Node.js may be at risk of denial of ser

🟠 High  |  Microsoft Security Response Center  |  12 Jul 2025

CVE-2026-15308: Python HTMLParser DoS on Azure

CVE-2026-15308 lets attackers exhaust CPU via Python's HTMLParser on Azure workloads. Learn the impact and how to mitigate this DoS risk.

🟠 High  |  Microsoft Security Response Center  |  12 Jul 2025

CVE-2026-14428: Microsoft Edge Dawn Input Validation Flaw

CVE-2026-14428 affects the Dawn WebGPU component in Chromium-based Microsoft Edge. Update your browser to mitigate this input validation vulnerability.

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-13777: Chromium Input Validation Flaw in Edge

CVE-2026-13777 affects Chromium's iOS web input validation, impacting Microsoft Edge. Learn what cloud security teams should do now.

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-14397: Edge ANGLE Out of Bounds Write Fix

CVE-2026-14397 is an out of bounds write flaw in ANGLE affecting Chromium-based browsers including Microsoft Edge. Update immediately to mitigate risk.

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-14396: Edge ANGLE Out-of-Bounds Read Fix

CVE-2026-14396 is an out-of-bounds read in ANGLE affecting Chromium-based Microsoft Edge. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-13778: Use After Free in Edge WebUSB

CVE-2026-13778 is a use-after-free flaw in Chromium's WebUSB component affecting Microsoft Edge. Update Edge immediately to mitigate exploitation risk.

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-14401: Microsoft Edge ANGLE Input Flaw

CVE-2026-14401 affects Microsoft Edge via a Chromium ANGLE input validation flaw. Learn the security impact and steps to protect your environment.

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-14412 Microsoft Edge ANGLE Input Validation Flaw

CVE-2026-14412 affects Microsoft Edge via a Chromium ANGLE vulnerability. Learn the security impact and recommended remediation steps for cloud environment

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-14410: Skia Flaw in Microsoft Edge & Chromium

CVE-2026-14410 affects the Skia graphics library in Chromium-based browsers including Microsoft Edge. Update Edge immediately to mitigate risk.

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-14409: Chromium V8 Flaw Affects Microsoft Edge

CVE-2026-14409 is a Chromium V8 implementation flaw affecting Microsoft Edge. Learn the security impact and patching advice for cloud environments.

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-14407: Chromium V8 Flaw Affects Microsoft Edge

CVE-2026-14407 is a Chromium V8 inappropriate implementation vulnerability affecting Microsoft Edge. Learn the security impact and recommended actions.

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-14406: Out-of-Bounds Read in Edge V8

CVE-2026-14406 is an out-of-bounds read in Chromium's V8 engine affecting Microsoft Edge. Update Edge immediately to mitigate memory leak risks.

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-14405: V8 Uninitialized Use in Microsoft Edge

CVE-2026-14405 is a V8 uninitialized memory vulnerability in Chromium affecting Microsoft Edge. Learn the security impact and patching advice.

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-14404: Edge PDFium Flaw – Azure Security

CVE-2026-14404 affects PDFium in Chromium-based Microsoft Edge. Learn what cloud security teams should do to mitigate this browser vulnerability.

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-14403: Use After Free in V8 – Edge & Azure

CVE-2026-14403 is a use-after-free flaw in Chrome's V8 engine affecting Microsoft Edge. Learn the security impact and remediation steps for cloud environme

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-14402: Uninitialized Use in ANGLE – Edge Fix

CVE-2026-14402 is an uninitialized use flaw in ANGLE affecting Chromium-based Microsoft Edge. Update Edge immediately to mitigate potential exploitation.

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-14400: ANGLE Out-of-Bounds Write in Microsoft Edge

CVE-2026-14400 is an out-of-bounds write flaw in Chromium's ANGLE library affecting Microsoft Edge. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-14399: Uninitialized Use in Dawn – Edge Fix

CVE-2026-14399 affects the Dawn WebGPU component in Chromium and Microsoft Edge. Learn what cloud security teams should do to mitigate this High severity f

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-14398: Use-After-Free in Chromium ANGLE | Edge

CVE-2026-14398 is a use-after-free flaw in Chromium's ANGLE graphics layer affecting Microsoft Edge. Patch immediately to prevent potential code execution.

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-14395: Edge Chromium V8 Out-of-Bounds Write

CVE-2026-14395 is a high-severity out-of-bounds write flaw in Chromium's V8 engine affecting Microsoft Edge. Update browsers immediately to mitigate risk.

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-14394: Use-After-Free in V8 Affects Edge

CVE-2026-14394 is a use-after-free flaw in Chromium's V8 engine affecting Microsoft Edge. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  11 Jul 2025

CVE-2026-56288: GNU patch Flaw Affects Azure

Microsoft flags CVE-2026-56288, a NULL pointer dereference in GNU patch, as affecting Azure. Learn the risk and how to remediate affected Linux workloads.

🟠 High  |  Microsoft Security Response Center  |  10 Jul 2025

CVE-2026-59818: etcd CRL Revocation Bypass in Azure

CVE-2026-59818 allows revoked TLS client certificates to authenticate to etcd gRPC listeners, bypassing CRL enforcement. Critical risk for Kubernetes on Az

🟠 High  |  Microsoft Security Response Center  |  10 Jul 2025

CVE-2026-53359: KVM Shadow Paging Use-After-Free on Azure

CVE-2026-53359 is a KVM x86 use-after-free flaw in shadow paging that could allow privilege escalation in Azure virtualised environments.

🟠 High  |  Microsoft Security Response Center  |  9 Jul 2025

CVE-2026-14355: PHP OpenSSL Memory Corruption on Azure

CVE-2026-14355 exposes a memory corruption flaw in PHP's OpenSSL extension via AES-WRAP-PAD. Azure PHP workloads should patch immediately.

🟠 High  |  Microsoft Security Response Center  |  9 Jul 2025

CVE-2026-8925: Azure SASL Double-Free Vulnerability

CVE-2026-8925 is a SASL double-free memory flaw affecting Azure. Learn the security impact and mitigation steps for cloud architects.

🟠 High  |  Microsoft Security Response Center  |  9 Jul 2025

CVE-2026-11856: Azure Cross-Origin Digest Auth Leak

CVE-2026-11856 exposes a cross-origin Digest auth state leak in Azure. Learn the security impact and what cloud architects should do now.

🟠 High  |  Microsoft Security Response Center  |  9 Jul 2025

CVE-2026-9547: Azure SSH Host Validation Flaw

CVE-2026-9547 exposes an SSH improper host validation flaw in Azure, risking man-in-the-middle attacks on secure administrative connections.

🟠 High  |  Microsoft Security Response Center  |  9 Jul 2025

CVE-2025-61727: Go x509 Wildcard DNS Constraint Bypass

CVE-2025-61727 exposes a flaw in Go's crypto/x509 package allowing wildcard TLS certificates to bypass DNS name constraints, risking domain spoofing.

🟠 High  |  Microsoft Security Response Center  |  9 Jul 2025

CVE-2025-58188: Go crypto/x509 DSA Cert Panic

CVE-2025-58188 causes a denial-of-service panic in Go's crypto/x509 when handling DSA public key certificates. Azure workloads using Go are at risk.

🟠 High  |  Microsoft Security Response Center  |  9 Jul 2025

CVE-2025-61724: Go net/textproto CPU DoS on Azure

CVE-2025-61724 affects Go's net/textproto package, enabling excessive CPU consumption. Learn the impact on Azure workloads and how to remediate.

🟠 High  |  Microsoft Security Response Center  |  9 Jul 2025

CVE-2026-42980: NT Kernel Privilege Escalation on Azure

CVE-2026-42980 is a Windows NT OS Kernel elevation of privilege flaw. Latest update is acknowledgement-only — no new patches or mitigations issued.

🟠 High  |  Microsoft Security Response Center  |  8 Jul 2025

CVE-2026-58525: Microsoft Edge Security Bypass Fix

CVE-2026-58525 allows remote attackers to bypass security features in Microsoft Edge (Chromium-based). Learn the risk and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  8 Jul 2025

CVE-2026-45638 WinSock EoP Vulnerability – Azure Impact

CVE-2026-45638 is a Windows WinSock elevation of privilege flaw affecting Azure VMs and Windows servers. Acknowledgement update — no new patches issued.

🟠 High  |  Microsoft Security Response Center  |  7 Jul 2025

CVE-2026-9080: Azure UAF Socket Callback Vulnerability

CVE-2026-9080 is a Use-After-Free vulnerability in socket callbacks affecting Azure. Learn the security impact and mitigation steps.

🟠 High  |  Microsoft Security Response Center  |  7 Jul 2025

CVE-2026-8926: Azure Password Leak via netrc & URL

CVE-2026-8926 exposes passwords when netrc files and user credentials appear in URLs. Learn the Azure security impact and mitigation steps.

🟠 High  |  Microsoft Security Response Center  |  7 Jul 2025

CVE-2026-8286: Azure STARTTLS Connection Reuse Flaw

CVE-2026-8286 exposes a STARTTLS connection reuse bug in Azure, potentially allowing credential exposure or man-in-the-middle attacks on encrypted sessions

🟠 High  |  Microsoft Security Response Center  |  7 Jul 2025

CVE-2026-8458: Azure Credential Reuse Vulnerability

CVE-2026-8458 affects Microsoft Azure, involving wrong credential reuse across services. Learn the risks and how to protect your cloud environment.

🟠 High  |  Microsoft Security Response Center  |  7 Jul 2025

CVE-2026-8924: Azure Trailing Dot Domain Super Cookie Flaw

CVE-2026-8924 exploits trailing dot domains to set super cookies in Azure environments, risking session hijacking and cross-domain data leakage.

🟠 High  |  Microsoft Security Response Center  |  7 Jul 2025

CVE-2026-8932: Azure mTLS Connection Reuse Flaw

CVE-2026-8932 exposes an incomplete mTLS config matching bug in Azure connection reuse, potentially bypassing mutual authentication controls.

🟠 High  |  Microsoft Security Response Center  |  7 Jul 2025

CVE-2026-9545: Azure HTTP/3 Early Data Exposure

CVE-2026-9545 exposes sensitive data via HTTP/3 early data in Azure. Learn the security impact and what architects should do now.

🟠 High  |  Microsoft Security Response Center  |  7 Jul 2025

CVE-2026-14647: ONNX Runtime Out-of-Bounds Flaw

CVE-2026-14647 is an out-of-bounds vulnerability in ONNX Runtime affecting Azure AI workloads. Learn the impact and mitigation steps.

🟠 High  |  Microsoft Security Response Center  |  7 Jul 2025

CVE-2026-12480: Keras HDF5 Arbitrary File Read Flaw

CVE-2026-12480 allows arbitrary file reads in Keras via HDF5 virtual dataset bypass. Learn the impact on Azure ML and cloud AI workloads.

🟠 High  |  Microsoft Security Response Center  |  7 Jul 2025

CVE-2026-54891: TLS Plaintext Injection Flaw in Azure SSL

CVE-2026-54891 allows plaintext APPLICATION_DATA injected during TLS handshake to reach client apps post-handshake, undermining transport security in Azure

🟠 High  |  Microsoft Security Response Center  |  7 Jul 2025

CVE-2026-54886: Azure SSH SFTP DoS Vulnerability

CVE-2026-54886 exposes Azure SSH SFTP servers to denial of service via an infinite loop triggered by malformed extended channel data. Patch now.

🟠 High  |  Microsoft Security Response Center  |  7 Jul 2025

CVE-2026-55952: Azure TLS 1.3 DoS Vulnerability

CVE-2026-55952 allows attackers to crash Azure services via a malformed TLS 1.3 ClientHello PSK extension. Patch and mitigate now.

🟠 High  |  Microsoft Security Response Center  |  7 Jul 2025

CVE-2026-14125: ANGLE Uninitialized Use in Microsoft Edge

CVE-2026-14125 affects the ANGLE graphics layer in Chromium-based Microsoft Edge. Learn what cloud security teams should do to mitigate this vulnerability.

🟠 High  |  Microsoft Security Response Center  |  3 Jul 2025

CVE-2026-13775: Use After Free in Chromium GPU – Edge

CVE-2026-13775 is a use-after-free flaw in Chromium's GPU component affecting Microsoft Edge. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  3 Jul 2025

CVE-2026-14153: Chromium Glic Flaw Affects Microsoft Edge

CVE-2026-14153 is a Chromium Glic implementation flaw affecting Microsoft Edge. Learn what cloud security teams should do to mitigate risk.

🟠 High  |  Microsoft Security Response Center  |  3 Jul 2025

CVE-2026-56646: Microsoft Edge Spoofing Vulnerability

CVE-2026-56646 is a spoofing vulnerability in Microsoft Edge (Chromium-based) exposing sensitive data to unauthorised network attackers. Patch immediately.

🟠 High  |  Microsoft Security Response Center  |  3 Jul 2025

CVE-2026-57983: Microsoft Edge Security Bypass Flaw

CVE-2026-57983 allows remote attackers to bypass security features in Microsoft Edge. Learn the risk and how to protect your cloud environments.

🟠 High  |  Microsoft Security Response Center  |  3 Jul 2025

CVE-2026-57985: Microsoft Edge RCE Vulnerability

CVE-2026-57985 is a remote code execution flaw in Microsoft Edge (Chromium-based). Learn the impact and how to protect your cloud environment.

🟠 High  |  Microsoft Security Response Center  |  3 Jul 2025

CVE-2026-57987: Microsoft Edge SSRF Spoofing Flaw

CVE-2026-57987 is an SSRF spoofing vulnerability in Microsoft Edge (Chromium-based) allowing unauthenticated network attackers to forge requests. Patch now

🟠 High  |  Microsoft Security Response Center  |  3 Jul 2025

CVE-2026-57993: Microsoft Edge SSRF Spoofing Flaw

CVE-2026-57993 is an SSRF vulnerability in Microsoft Edge (Chromium-based) enabling unauthenticated network spoofing. Learn the security impact and mitigat

🟠 High  |  Microsoft Security Response Center  |  3 Jul 2025

CVE-2026-58282: Microsoft Edge Spoofing Vulnerability

CVE-2026-58282 affects Microsoft Edge (Chromium-based), enabling network attackers to spoof content via improper access controls. Patch immediately.

🟠 High  |  Microsoft Security Response Center  |  3 Jul 2025

CVE-2026-58283: Microsoft Edge Spoofing Vulnerability

CVE-2026-58283 is a type confusion flaw in Microsoft Edge allowing network-based spoofing attacks. Learn the impact and mitigation steps for enterprise env

🟠 High  |  Microsoft Security Response Center  |  3 Jul 2025

CVE-2026-58287: Microsoft Edge RCE Vulnerability

CVE-2026-58287 is a use-after-free flaw in Microsoft Edge allowing remote code execution without authentication. Patch immediately.

🟠 High  |  Microsoft Security Response Center  |  3 Jul 2025

CVE-2026-58299: Microsoft Edge Android RCE Flaw

CVE-2026-58299 is a race condition RCE vulnerability in Microsoft Edge for Android allowing unauthenticated remote code execution over a network.

🟠 High  |  Microsoft Security Response Center  |  3 Jul 2025

CVE-2026-26145: Azure Synapse Privilege Escalation

CVE-2026-26145 allows authorised attackers to escalate privileges in Azure Synapse Analytics over a network. Learn the risk and how to respond.

🟠 High  |  Microsoft Security Response Center  |  2 Jul 2025

CVE-2026-41106: M365 Copilot Privilege Escalation

CVE-2026-41106 is an open redirect vulnerability in Microsoft 365 Copilot that enables unauthenticated privilege escalation over a network.

🟠 High  |  Microsoft Security Response Center  |  2 Jul 2025

CVE-2026-45499: Azure OpenAI SSRF Privilege Escalation

CVE-2026-45499 is an SSRF vulnerability in Azure OpenAI enabling authenticated attackers to escalate privileges over a network. Learn the risks and mitigat

🟠 High  |  Microsoft Security Response Center  |  2 Jul 2025

CVE-2026-50521: Microsoft Edge RCE Vulnerability

Microsoft Edge (Chromium-based) is affected by a remote code execution vulnerability CVE-2026-50521. Update to the latest Edge version immediately.

🟠 High  |  Microsoft Security Response Center  |  2 Jul 2025

CVE-2026-54998: Exchange Online Privilege Escalation

CVE-2026-54998 allows authenticated attackers to elevate privileges in Microsoft Exchange Online. Learn the impact and what architects should do now.

🟠 High  |  Microsoft Security Response Center  |  2 Jul 2025

CVE-2026-57100: Microsoft Entra SSRF Privilege Escalation

CVE-2026-57100 is an SSRF flaw in Microsoft Entra Provisioning Service (SyncFabric) enabling privilege escalation. Learn the impact and mitigation steps.

🟠 High  |  Microsoft Security Response Center  |  2 Jul 2025

CVE-2026-57062: GnuPG AES-GCM CMS Parsing Flaw

CVE-2026-57062 exposes a GnuPG CMS parsing flaw where a 4-byte AES-GCM ICV is accepted instead of 12 bytes, weakening encrypted message integrity.

🟠 High  |  Microsoft Security Response Center  |  1 Jul 2025

CVE-2026-7532: wolfSSL IP Name Constraint Bypass

CVE-2026-7532 exposes a wolfSSL flaw where IP name constraints go unenforced, risking certificate validation bypass in Azure and other workloads.

🟠 High  |  Microsoft Security Response Center  |  1 Jul 2025

CVE-2026-6291: Azure Bleichenbacher RSA Padding Oracle

CVE-2026-6291 exposes a Bleichenbacher padding oracle in Azure PKCS#7 KTRI RSA PKCS#1 v1.5 decryption, risking cryptographic key exposure.

🟠 High  |  Microsoft Security Response Center  |  1 Jul 2025

CVE-2026-57918: libnfs Integer Underflow Flaw

CVE-2026-57918 is an integer underflow bug in libnfs ≤6.0.2 that can be triggered by a crafted NFS server, risking memory corruption on client systems.

🟠 High  |  Microsoft Security Response Center  |  1 Jul 2025

CVE-2026-13325: KubeVirt DisableTLS Exposes Unauthenticated

CVE-2026-13325 in KubeVirt's disableTLS setting removes authentication from virtqemud proxy on all interfaces, risking unauthorised VM access on Azure.

🟠 High  |  Microsoft Security Response Center  |  1 Jul 2025

CVE-2026-13218: KubeVirt Host File Overwrite Flaw

CVE-2026-13218 is a KubeVirt symlink vulnerability allowing virt-launcher to overwrite host files. Learn the risk and mitigation steps for Azure Kubernetes

🟠 High  |  Microsoft Security Response Center  |  1 Jul 2025

CVE-2026-13208: KubeVirt virt-handler Auth Bypass

CVE-2026-13208 exposes a KubeVirt virt-handler flaw where unauthenticated gRPC requests can spoof VMI identity, risking VM integrity on Azure Kubernetes cl

🟠 High  |  Microsoft Security Response Center  |  1 Jul 2025

CVE-2026-13322: KubeVirt virt-handler OOM DoS Flaw

CVE-2026-13322 is a KubeVirt denial-of-service vulnerability in virt-handler. Unbounded virtio-serial reads cause OOM crashes affecting Azure Kubernetes wo

🟠 High  |  Microsoft Security Response Center  |  1 Jul 2025

CVE-2026-58014: GLib Off-by-One Flaw Affects Azure

CVE-2026-58014 is an off-by-one error in GLib's key file parser, potentially enabling memory corruption on Azure Linux workloads. Patch now.

🟠 High  |  Microsoft Security Response Center  |  1 Jul 2025

CVE-2026-58012: GLib Buffer Over-Read in Azure Workloads

CVE-2026-58012 is a GLib buffer over-read flaw in g_regex_replace() affecting Azure and Linux workloads. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  1 Jul 2025

CVE-2026-58016: GLib Integer Underflow in Azure Workloads

CVE-2026-58016 is a GLib integer underflow flaw in D-Bus XML parsing that may allow memory corruption or code execution on Azure Linux workloads.

🟠 High  |  Microsoft Security Response Center  |  1 Jul 2025

CVE-2026-58015: GLib Path Traversal Flaw on Azure

CVE-2026-58015 is a path traversal vulnerability in GLib's D-Bus SHA-1 auth mechanism affecting Azure Linux workloads. Patch promptly.

🟠 High  |  Microsoft Security Response Center  |  1 Jul 2025

CVE-2026-58010: GLib Buffer Over-Read in Azure Linux

CVE-2026-58010 is a GLib buffer over-read vulnerability affecting Azure Linux workloads. Learn the risk and how to remediate affected systems.

🟠 High  |  Microsoft Security Response Center  |  1 Jul 2025

CVE-2026-42910 Windows Hotpatch EoP Vulnerability

CVE-2026-42910 affects the Windows Hotpatch Monitoring Service with an elevation of privilege risk. Latest update is acknowledgement-only. Learn what Azure

🟠 High  |  Microsoft Security Response Center  |  30 Jun 2025

CVE-2026-11979: libxml2 Buffer Overflow Hits Azure

CVE-2026-11979 is a stack-based buffer overflow in libxml2 affecting Azure. Learn the risks and how to protect your cloud workloads.

🟠 High  |  Microsoft Security Response Center  |  30 Jun 2025

CVE-2026-41992: GNU gzip Buffer Overflow on Azure

Microsoft flags CVE-2026-41992, a global buffer overflow in GNU gzip, affecting Azure environments. Learn the risk and how to remediate.

🟠 High  |  Microsoft Security Response Center  |  30 Jun 2025

CVE-2026-54371: attr Symlink Traversal Privilege Escalation

CVE-2026-54371 affects attr < 2.6.0, enabling symlink traversal privilege escalation via getfattr/setfattr on Linux systems including Azure workloads.

🟠 High  |  Microsoft Security Response Center  |  30 Jun 2025

CVE-2026-54369: Linux ACL Symlink Privilege Escalation

CVE-2026-54369 affects acl < 2.4.0 on Linux, enabling symlink traversal privilege escalation via libacl. Azure workloads running Linux may be at risk.

🟠 High  |  Microsoft Security Response Center  |  30 Jun 2025

CVE-2026-58058: Nmap IPv6 Integer Underflow Flaw

CVE-2026-58058 is an integer underflow in Nmap's IPv6 extension header parsing. Learn the risk and mitigation steps for Azure security teams.

🟠 High  |  Microsoft Security Response Center  |  29 Jun 2025

CVE-2026-58055: nghttp2 nghttpx HTTP Smuggling Flaw

CVE-2026-58055 affects nghttp2 nghttpx, enabling HTTP request/response smuggling via Upgrade requests. Azure workloads using nghttpx should patch immediate

🟠 High  |  Microsoft Security Response Center  |  29 Jun 2025

CVE-2026-58051: libssh2 Uninitialised Pointer Flaw on Azure

CVE-2026-58051 is a libssh2 memory corruption flaw affecting Azure workloads. Learn the risk and how to remediate this uninitialised pointer vulnerability.

🟠 High  |  Microsoft Security Response Center  |  29 Jun 2025

CVE-2026-58050: libssh2 Integer Overflow in Azure

CVE-2026-58050 is a libssh2 integer overflow flaw affecting Azure workloads. Learn the risk, impact, and remediation steps for cloud engineers.

🟠 High  |  Microsoft Security Response Center  |  29 Jun 2025

CVE-2026-52908: Azure RDMA Memory Re-reg Flaw

CVE-2026-52908 affects the Linux RDMA subsystem's rereg_mr access validation. Learn the security impact for Azure HPC and RDMA workloads.

🟠 High  |  Microsoft Security Response Center  |  29 Jun 2025

CVE-2026-52909 Azure Linux Kernel ip6_vti Flaw

CVE-2026-52909 affects the Linux kernel ip6_vti subsystem on Azure. Learn the risk and mitigation steps for cloud security teams.

🟠 High  |  Microsoft Security Response Center  |  29 Jun 2025

CVE-2026-52910: Azure Linux Kernel BPF Use-After-Free

CVE-2026-52910 is a Linux kernel BPF use-after-free flaw affecting Azure workloads. Patch Linux VMs and AKS nodes promptly to mitigate risk.

🟠 High  |  Microsoft Security Response Center  |  29 Jun 2025

CVE-2023-6606: Linux Kernel SMB Out-of-Bounds Read

CVE-2023-6606 is a Linux kernel out-of-bounds read flaw in smbCalcSize, affecting Azure Linux VMs. Learn the impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  28 Jun 2025

CVE-2025-40158: Azure Linux Kernel IPv6 RCU Flaw

CVE-2025-40158 affects the Linux kernel's IPv6 ip6_output() function. Learn the risk to Azure Linux VMs and what architects should do now.

🟠 High  |  Microsoft Security Response Center  |  28 Jun 2025

CVE-2025-40170: Linux Kernel Net Stack Flaw in Azure

CVE-2025-40170 is a Linux kernel networking vulnerability affecting Azure workloads. Learn the risk and remediation steps for cloud security teams.

🟠 High  |  Microsoft Security Response Center  |  28 Jun 2025

CVE-2025-40168: Azure Linux Kernel SMC Flaw

CVE-2025-40168 is a Linux kernel SMC use-after-free vulnerability affecting Azure VMs. Learn the impact and remediation steps for cloud architects.

🟠 High  |  Microsoft Security Response Center  |  28 Jun 2025

CVE-2025-40139: Linux Kernel SMC Flaw in Azure

CVE-2025-40139 is a Linux kernel SMC subsystem race condition flaw affecting Azure Linux workloads. Learn the impact and patching advice.

🟠 High  |  Microsoft Security Response Center  |  28 Jun 2025

CVE-2025-21825: Azure Linux BPF Timer Kernel Flaw

CVE-2025-21825 affects the Linux kernel BPF timer subsystem on PREEMPT_RT builds. Azure VM and container workloads may be at risk — patch promptly.

🟠 High  |  Microsoft Security Response Center  |  28 Jun 2025

CVE-2026-13038: Use After Free in Edge Autofill

CVE-2026-13038 is a use-after-free flaw in Chromium's Autofill component affecting Microsoft Edge. Update Edge immediately to mitigate potential code execu

🟠 High  |  Microsoft Security Response Center  |  27 Jun 2025

CVE-2026-13036: Use After Free in Blink – Edge Patch

CVE-2026-13036 is a use-after-free flaw in Chromium's Blink engine affecting Microsoft Edge. Update Edge immediately to mitigate potential code execution.

🟠 High  |  Microsoft Security Response Center  |  27 Jun 2025

CVE-2026-13035: Use After Free in Edge Bluetooth

CVE-2026-13035 is a use-after-free flaw in Chromium Bluetooth affecting Microsoft Edge. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  27 Jun 2025

CVE-2026-13033: Edge Chromium Out-of-Bounds Read Fix

Microsoft Edge inherits a Chromium out-of-bounds read fix (CVE-2026-13033) in Blink InterestGroups. Update Edge immediately to mitigate memory disclosure r

🟠 High  |  Microsoft Security Response Center  |  27 Jun 2025

CVE-2026-13031: Use-After-Free in Blink & MS Edge

CVE-2026-13031 is a use-after-free flaw in Chromium's Blink engine affecting Microsoft Edge. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  27 Jun 2025

CVE-2026-13029: Edge Chromium Web Auth Use-After-Free

CVE-2026-13029 is a use-after-free flaw in Chromium's Web Authentication component affecting Microsoft Edge. Learn the security impact and remediation step

🟠 High  |  Microsoft Security Response Center  |  27 Jun 2025

CVE-2026-13027 Use After Free in Chromium FileSystem

CVE-2026-13027 is a use-after-free flaw in Chromium's FileSystem component affecting Microsoft Edge. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  27 Jun 2025

CVE-2026-13026: Chromium Use-After-Free in Edge

CVE-2026-13026 is a use-after-free flaw in Chromium's Digital Credentials component affecting Microsoft Edge. Learn the security impact and remediation ste

🟠 High  |  Microsoft Security Response Center  |  27 Jun 2025

CVE-2026-13025: Chromium DevTools Input Validation Flaw

CVE-2026-13025 affects Chromium DevTools with insufficient input validation. Microsoft Edge users should update immediately to receive the upstream fix.

🟠 High  |  Microsoft Security Response Center  |  27 Jun 2025

CVE-2026-13024: Edge Chromium Navigation Input Flaw

CVE-2026-13024 affects Microsoft Edge via a Chromium navigation flaw with insufficient input validation. Learn the impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  27 Jun 2025

CVE-2026-13023: Chromium GPU Flaw Affects Microsoft Edge

CVE-2026-13023 is an uninitialized memory use vulnerability in Chromium's GPU component affecting Microsoft Edge. Learn the security impact and remediation

🟠 High  |  Microsoft Security Response Center  |  27 Jun 2025

CVE-2026-13021: Chromium Edge DeviceBoundSession Flaw

CVE-2026-13021 affects Chromium's DeviceBoundSessionCredentials in Microsoft Edge. Learn about the risk and how to remediate across enterprise endpoints.

🟠 High  |  Microsoft Security Response Center  |  27 Jun 2025

CVE-2026-46320: Linux TAP Driver Flaw Affects Azure VMs

CVE-2026-46320 is a kernel memory flaw in tap_get_user_xdp() affecting Linux-based Azure workloads. Learn the risk and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  26 Jun 2025

CVE-2026-46321: Azure Linux Kernel TUN XDP Memory Flaw

CVE-2026-46321 is a Linux kernel memory leak in tun_xdp_one() affecting Azure Linux workloads. Patch now to prevent denial of service risk.

🟠 High  |  Microsoft Security Response Center  |  26 Jun 2025

CVE-2026-45850: Azure Linux IPVS IPv6 Checksum Flaw

CVE-2026-45850 affects the Linux kernel IPVS subsystem, skipping IPv6 extension header checksum checks. Key risk for Azure AKS and Linux VM workloads.

🟠 High  |  Microsoft Security Response Center  |  26 Jun 2025

CVE-2025-68736: Linux Landlock Directory Flaw on Azure

CVE-2025-68736 affects the Linux Landlock sandbox module, allowing potential filesystem access control bypass. Azure workloads should be patched promptly.

🟠 High  |  Microsoft Security Response Center  |  26 Jun 2025

CVE-2026-41086 Azure Windows Admin Center EoP Flaw

CVE-2026-41086 is an elevation of privilege vulnerability in Windows Admin Center via Azure Portal. Learn what architects should do to mitigate risk.

🟠 High  |  Microsoft Security Response Center  |  25 Jun 2025

CVE-2026-45637: Microsoft DWM Privilege Escalation

CVE-2026-45637 is a Microsoft DWM Core Library elevation of privilege flaw. Latest update is informational only — no new patches required.

🟠 High  |  Microsoft Security Response Center  |  25 Jun 2025

CVE-2026-11816 Path Traversal in Keras – Azure Risk

CVE-2026-11816 exposes a path traversal flaw in keras-team/keras, putting Azure-hosted ML pipelines at risk. Patch now and review file access controls.

🟠 High  |  Microsoft Security Response Center  |  25 Jun 2025

CVE-2026-33840 Win32k Privilege Escalation – Azure

Microsoft updates acknowledgement for CVE-2026-33840, a Win32k elevation of privilege flaw. Learn the impact for Azure Windows VM workloads and what to che

🟠 High  |  Microsoft Security Response Center  |  23 Jun 2025

CVE-2026-45504 Exchange Server Privilege Escalation

CVE-2026-45504 is a Microsoft Exchange Server Elevation of Privilege flaw. This update adds an acknowledgement — no new patches required.

🟠 High  |  Microsoft Security Response Center  |  23 Jun 2025

CVE-2026-46331: Linux net/sched Pedit Page Cache Bug

CVE-2026-46331 is a Linux kernel net/sched pedit flaw causing page cache corruption. Azure Linux VM and AKS users should patch promptly.

🟠 High  |  Microsoft Security Response Center  |  20 Jun 2025

CVE-2026-45446: AES-GCM-SIV Empty Message Tag Flaw

CVE-2026-45446 exposes a tag processing flaw in AES-GCM-SIV and AES-SIV modes for empty messages, risking authentication bypass and data forgery.

🟠 High  |  Microsoft Security Response Center  |  20 Jun 2025

CVE-2026-34183: Azure QUIC Memory Vulnerability

CVE-2026-34183 causes unbounded memory growth in Azure's QUIC PATH_CHALLENGE handler, risking denial-of-service. Patch and mitigate now.

🟠 High  |  Microsoft Security Response Center  |  20 Jun 2025

CVE-2025-4574: crossbeam-channel Double Free Flaw

CVE-2025-4574 affects the Rust crossbeam-channel crate with a double-free vulnerability on drop, posing memory corruption risks in Azure and Rust-based ser

🟠 High  |  Microsoft Security Response Center  |  20 Jun 2025

CVE-2026-44817 Microsoft Excel RCE for Mac

CVE-2026-44817 is a remote code execution flaw in Microsoft Excel for Mac. Learn what's affected and how to protect your organisation.

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-44818: Excel for Mac RCE Vulnerability

Microsoft patches CVE-2026-44818, a remote code execution flaw in Excel for Mac. Find out what's affected and how to protect your organisation.

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-44819: Microsoft Office for Mac RCE Vulnerability

Microsoft patches CVE-2026-44819, a remote code execution flaw in Office for Mac. Learn what's affected and the steps to protect your organisation.

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-44820 Microsoft Excel RCE for Mac Patched

Microsoft patches CVE-2026-44820, a remote code execution flaw in Excel for Mac. Cloud architects should prioritise patching via MDM to prevent potential c

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-44823: Microsoft Excel RCE Flaw for Mac

Microsoft patches CVE-2026-44823, a remote code execution vulnerability in Excel for Mac. Learn what's affected and how to protect your organisation.

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-44824: Microsoft Office for Mac RCE Flaw

CVE-2026-44824 is a remote code execution flaw in Microsoft Office for Mac. Apply the latest security update to protect affected devices.

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-45456: Microsoft Outlook & Word RCE on macOS

Microsoft patches CVE-2026-45456, a remote code execution flaw in Outlook and Word for Mac. Learn what action cloud security teams need to take.

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-45458: Microsoft Outlook & Word RCE Fix

Microsoft patches CVE-2026-45458, a remote code execution flaw in Outlook and Word for Mac. Mac users should update immediately to stay protected.

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-45460: Microsoft Office Android Info Disclosure

CVE-2026-45460 affects Microsoft Office for Android. Learn what this information disclosure vulnerability means and how to protect your organisation.

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-45461: MS Office Android RCE Vulnerability

Microsoft patches a remote code execution flaw in Office for Android (CVE-2026-45461). Apply the update immediately to protect corporate devices from explo

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-45469: Excel for Mac RCE Vulnerability

Microsoft patches CVE-2026-45469, a remote code execution flaw in Excel for Mac. Learn what's affected and how to protect your environment.

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-45471: Microsoft Word RCE for Mac Fix

Microsoft patches CVE-2026-45471, a remote code execution flaw in Microsoft Word for Mac. Update Office for Mac now to stay protected.

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-45472: Microsoft Office Android RCE Patch

Microsoft has patched CVE-2026-45472, a remote code execution flaw in Office for Android. Learn what cloud security architects should do now.

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-45474 Microsoft Office Android RCE Flaw

Microsoft patches CVE-2026-45474, a remote code execution flaw in Office for Android. Install the update immediately to protect corporate devices.

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-45486: Microsoft Word RCE Flaw for Mac

CVE-2026-45486 is a remote code execution vulnerability in Microsoft Word for Mac. Update Office for Mac immediately to mitigate the risk.

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-45643: Microsoft Word RCE Vulnerability for Mac

CVE-2026-45643 is a remote code execution flaw in Microsoft Word for Mac. Learn what's affected and how to patch it quickly.

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-10275: OpenSC pkcs11-tool Buffer Overflow

CVE-2026-10275 is a buffer overflow in OpenSC pkcs11-tool affecting key generation. Learn the risk to Azure and hybrid HSM environments and how to mitigate

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-8376: Perl Heap Buffer Overflow on Azure

CVE-2026-8376 is a heap buffer overflow in Perl up to 5.43.10 on 32-bit builds affecting Azure workloads. Learn the risk and mitigation steps.

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-43966: HTTP Response Splitting Azure Flaw

CVE-2026-43966 details an HTTP Response Splitting vulnerability in cow_http_struct_hd on Azure. Learn the impact and how to remediate.

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-9669: Azure Python bz2 Stack Buffer Overflow

CVE-2026-9669 is a stack buffer overflow in Python's bz2.BZ2Decompressor affecting Azure workloads. Learn the risk and mitigation steps.

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-53689: Azure Security Vulnerability Advisory

Microsoft has published CVE-2026-53689 affecting Azure. Learn what cloud security architects need to know and the recommended actions to take.

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-42014: GnuTLS Use-After-Free on Azure

CVE-2026-42014 is a use-after-free flaw in GnuTLS affecting PKCS#11 token PIN handling. Azure workloads using GnuTLS should patch immediately.

🟠 High  |  Microsoft Security Response Center  |  19 Jun 2025

CVE-2026-32174: Azure Bot Service Privilege Escalation

CVE-2026-32174 affects Azure Bot Service, allowing authenticated attackers to elevate privileges over a network. Learn the impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  18 Jun 2025

CVE-2026-32208: Microsoft Edge XSS Spoofing Flaw

CVE-2026-32208 is an XSS spoofing vulnerability in Microsoft Edge (Chromium-based). Learn the security impact and remediation steps for cloud environments.

🟠 High  |  Microsoft Security Response Center  |  18 Jun 2025

CVE-2026-42895: Microsoft Copilot Command Injection Flaw

CVE-2026-42895 is a command injection vulnerability in Microsoft Copilot allowing unauthenticated network attackers to tamper with the service. Patch now.

🟠 High  |  Microsoft Security Response Center  |  18 Jun 2025

CVE-2026-47633: Azure Cost Management Info Disclosure

CVE-2026-47633 allows unauthenticated attackers to disclose sensitive data via Azure Cost Management. Learn the impact and mitigation steps.

🟠 High  |  Microsoft Security Response Center  |  18 Jun 2025

CVE-2026-47645: M365 Copilot Privilege Escalation

CVE-2026-47645 is an open redirect vulnerability in Microsoft 365 Copilot Business Chat enabling privilege escalation over a network. Learn the risks and m

🟠 High  |  Microsoft Security Response Center  |  18 Jun 2025

CVE-2026-47646: Dynamics 365 Customer Voice XSS Flaw

CVE-2026-47646 is an XSS spoofing vulnerability in Microsoft Dynamics 365 Customer Voice exploitable by unauthenticated attackers over a network.

🟠 High  |  Microsoft Security Response Center  |  18 Jun 2025

CVE-2026-47647: Dynamics 365 Privilege Escalation

CVE-2026-47647 is a Dynamics 365 elevation of privilege flaw allowing authenticated attackers to escalate permissions over a network. Patch now.

🟠 High  |  Microsoft Security Response Center  |  18 Jun 2025

CVE-2026-48582: Exchange Online Privilege Escalation

CVE-2026-48582 is a Microsoft Exchange Online elevation of privilege flaw allowing authenticated attackers to gain higher permissions over a network.

🟠 High  |  Microsoft Security Response Center  |  18 Jun 2025

CVE-2026-48584: Azure Synapse Privilege Escalation

CVE-2026-48584 allows authenticated attackers to escalate privileges in Azure Synapse Analytics over a network. Learn the risk and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  18 Jun 2025

CVE-2026-54130: M365 Copilot Info Disclosure Flaw

CVE-2026-54130 exposes M365 Copilot to unauthenticated information disclosure over a network. Learn the impact and how to protect your organisation.

🟠 High  |  Microsoft Security Response Center  |  18 Jun 2025

CVE-2026-46274: Linux io-wq Kernel Flaw Affects Azure

CVE-2026-46274 fixes a missing hash check in Linux io_wq_remove_pending(), risking memory corruption on Azure Linux VMs and AKS workloads.

🟠 High  |  Microsoft Security Response Center  |  18 Jun 2025

CVE-2026-28387: Azure DANE Client Use-After-Free Flaw

CVE-2026-28387 is a use-after-free bug in DANE client code affecting Azure. Learn the risks and what cloud architects should do now.

🟠 High  |  Microsoft Security Response Center  |  18 Jun 2025

CVE-2026-9076: CMS Decryption Out-of-Bounds Read | Azure

CVE-2026-9076 is an out-of-bounds read flaw in CMS password-based decryption affecting Microsoft/Azure. Learn the risk and recommended mitigations.

🟠 High  |  Microsoft Security Response Center  |  18 Jun 2025

CVE-2026-34180: Azure ASN.1 Heap Buffer Over-read

CVE-2026-34180 is a heap buffer over-read in ASN.1 parsing affecting Azure. Learn the security impact and remediation steps for cloud architects.

🟠 High  |  Microsoft Security Response Center  |  18 Jun 2025

CVE-2026-42767: Azure CRMF NULL Pointer Dereference

CVE-2026-42767 is a NULL pointer dereference in CRMF EncryptedValue decryption affecting Azure. Learn the security impact and recommended mitigations.

🟠 High  |  Microsoft Security Response Center  |  18 Jun 2025

CVE-2026-7383: Azure ASN.1 Heap Buffer Overflow

CVE-2026-7383 details a heap buffer overflow in ASN.1 multibyte string conversion affecting Azure. Learn the security impact and mitigation steps.

🟠 High  |  Microsoft Security Response Center  |  18 Jun 2025

CVE-2026-25681: Go net/html DOCTYPE Parsing Flaw

CVE-2026-25681 affects golang.org/x/net/html, causing incorrect DOCTYPE character reference handling. Azure workloads using Go may be at risk.

🟠 High  |  Microsoft Security Response Center  |  18 Jun 2025

CVE-2026-25680: Go net/html DoS Vulnerability on Azure

CVE-2026-25680 is a denial-of-service flaw in golang.org/x/net/html affecting Go apps on Azure. Learn the impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  18 Jun 2025

CVE-2026-48854: elixir-grpc Memory Exhaustion DoS

CVE-2026-48854 allows attackers to exhaust server memory via unbounded gRPC request bodies in elixir-grpc, risking denial of service on Azure-hosted worklo

🟠 High  |  Microsoft Security Response Center  |  18 Jun 2025

CVE-2026-35433: .NET Elevation of Privilege Flaw

Microsoft updates CVE-2026-35433, a .NET Elevation of Privilege vulnerability, removing Windows 11 21H1 and 22H2 from the affected platforms list.

🟠 High  |  Microsoft Security Response Center  |  17 Jun 2025

CVE-2026-42828 Windows ProjFS Privilege Escalation

CVE-2026-42828 is a Windows Projected File System elevation of privilege flaw. Learn what it means for Azure and hybrid Windows environments.

🟠 High  |  Microsoft Security Response Center  |  17 Jun 2025

CVE-2026-45475 Microsoft Office RCE Vulnerability

CVE-2026-45475 is a Microsoft Office remote code execution flaw. Learn the security impact and patching guidance for cloud security teams.

🟠 High  |  Microsoft Security Response Center  |  17 Jun 2025

CVE-2026-47636 SharePoint Server Spoofing Flaw

CVE-2026-47636 is a spoofing vulnerability in Microsoft SharePoint Server. Learn what it means for your environment and what action to take.

🟠 High  |  Microsoft Security Response Center  |  17 Jun 2025

CVE-2026-40371: Dynamics 365 On-Prem EoP Fix

Microsoft corrects patch guidance for CVE-2026-40371, a Dynamics 365 on-premises privilege escalation flaw. The real fix is in v9.1 Update 1.45.

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-42915 Windows VMSwitch DoS Vulnerability

CVE-2026-42915 is a Denial of Service flaw in Windows VMSwitch affecting Hyper-V and Azure. Advisory updated with corrected title and description.

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-50656: Microsoft Defender EoP Vulnerability

CVE-2026-50656 'RoguePlanet' is an unpatched elevation of privilege flaw in the Microsoft Malware Protection Engine. Learn the risks and mitigations.

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-34182: Azure CMS AuthEnvelopedData Forgery Flaw

CVE-2026-34182 allows forged CMS AuthEnvelopedData messages to be accepted as valid, threatening message integrity in Azure environments. Patch now.

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-54411: Linux-PAM Timing Attack Exposes Passwords

CVE-2026-54411 exposes a timing side-channel in Linux-PAM's pam_userdb module, allowing attackers to recover plaintext passwords via response-time analysis

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-11642: Use-After-Free in Edge Web Apps

CVE-2026-11642 is a use-after-free flaw in Chromium's Web Apps component affecting Microsoft Edge. Update Edge immediately to mitigate code execution risk.

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-11641: Chromium Bluetooth Use-After-Free in Edge

CVE-2026-11641 is a use-after-free flaw in Chromium's Bluetooth component affecting Microsoft Edge. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-11640: Integer Overflow in libyuv | Microsoft Edge

CVE-2026-11640 is an integer overflow flaw in libyuv affecting Chromium-based Microsoft Edge. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-11639: Chromium Use-After-Free in MS Edge

CVE-2026-11639 is a use-after-free flaw in Chromium Compositing affecting Microsoft Edge. Learn the security impact and patching advice for cloud environme

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-11638: Use-After-Free in Edge Chromium Printing

CVE-2026-11638 is a use-after-free flaw in Chromium's Printing component affecting Microsoft Edge. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-11637: Use After Free in Microsoft Edge Chromium

CVE-2026-11637 is a use-after-free flaw in Chromium Views affecting Microsoft Edge. Learn the security impact and remediation steps for cloud environments.

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-11636: Use After Free in Edge Autofill

CVE-2026-11636 is a use-after-free flaw in Chromium Autofill affecting Microsoft Edge. Learn the security impact and recommended actions for cloud architec

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-11635: Chromium Bluetooth Use-After-Free in Edge

CVE-2026-11635 is a use-after-free flaw in Chromium's Bluetooth component affecting Microsoft Edge. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-11634: Use-After-Free in Chromium Gamepad

CVE-2026-11634 is a use-after-free flaw in Chromium's Gamepad component affecting Microsoft Edge. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-11633: Chromium Bluetooth Use-After-Free in Edge

CVE-2026-11633 is a use-after-free flaw in Chromium's Bluetooth component affecting Microsoft Edge. Update Edge immediately to mitigate potential code exec

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-11632: Use-After-Free in Edge TabStrip

CVE-2026-11632 is a use-after-free flaw in Chromium's TabStrip affecting Microsoft Edge. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-11631: Use-After-Free in Chromium Aura | Edge

CVE-2026-11631 is a use-after-free flaw in Chromium's Aura framework affecting Microsoft Edge. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-11630: Use-After-Free Flaw in Microsoft Edge

CVE-2026-11630 is a use-after-free vulnerability in Chromium's File Input component affecting Microsoft Edge. Update Edge immediately to mitigate risk.

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-11629: Use-After-Free in Chromium Ozone & Edge

CVE-2026-11629 is a use-after-free flaw in Chromium's Ozone layer affecting Microsoft Edge. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-11628: Chromium Use-After-Free in Edge

CVE-2026-11628 is a use-after-free flaw in Chromium's Ozone component affecting Microsoft Edge. Update Edge immediately to mitigate potential code executio

🟠 High  |  Microsoft Security Response Center  |  16 Jun 2025

CVE-2026-12019: Chromium Out-of-Bounds Write in Codecs

CVE-2026-12019 is an out-of-bounds write flaw in Chromium Codecs affecting Microsoft Edge. Learn the security impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  15 Jun 2025

CVE-2026-12016: Chromium DevTools Input Validation Flaw

CVE-2026-12016 affects Chromium DevTools via insufficient input validation. Microsoft Edge inherits this flaw — update immediately to mitigate risk.

🟠 High  |  Microsoft Security Response Center  |  15 Jun 2025

CVE-2026-12015: Edge Chromium Autofill Use-After-Free

CVE-2026-12015 is a use-after-free flaw in Chromium's Autofill component affecting Microsoft Edge. Learn the security impact and recommended actions.

🟠 High  |  Microsoft Security Response Center  |  15 Jun 2025

CVE-2026-12012: Use-After-Free in Microsoft Edge & Chromium

CVE-2026-12012 is a use-after-free flaw in Chromium's Network component affecting Microsoft Edge. Learn the impact and remediation steps.

🟠 High  |  Microsoft Security Response Center  |  15 Jun 2025

CVE-2026-12008: Edge Chromium Use-After-Free Flaw

CVE-2026-12008 is a use-after-free vulnerability in Chromium's DigitalCredentials component affecting Microsoft Edge. Update immediately to mitigate risk.

🟠 High  |  Microsoft Security Response Center  |  15 Jun 2025

CVE-2026-46433: lldpd Heap OOB Read in Azure

CVE-2026-46433 is a heap out-of-bounds read in lldpd affecting Azure environments. Learn the impact and remediation steps for cloud security teams.

🟠 High  |  Microsoft Security Response Center  |  15 Jun 2025

CVE-2026-49762: Azure Version Parsing DoS Vulnerability

CVE-2026-49762 exposes Azure to CPU and memory exhaustion via unbounded integer parsing in the Version module. Learn the risk and how to respond.

🟠 High  |  Microsoft Security Response Center  |  15 Jun 2025

CVE-2026-7774: Python tarfile Path Traversal on Azure

CVE-2026-7774 allows attackers to bypass Python's tarfile data_filter, writing files outside the extraction directory. Key risk for Azure cloud workloads.

🟠 High  |  Microsoft Security Response Center  |  15 Jun 2025

CVE-2026-11526: Perl GD OS Command Injection Flaw

CVE-2026-11526 affects Perl GD before v2.86, enabling OS command injection and file overwrite via unsafe two-arg open() calls. Patch now.

🟠 High  |  Microsoft Security Response Center  |  15 Jun 2025

CVE-2026-42768 Bleichenbacher Oracle in CMS & PKCS7 Decrypt

CVE-2026-42768 exposes a Bleichenbacher padding oracle in CMS_decrypt() and PKCS7_decrypt(), risking plaintext or key recovery in multi-recipient encrypted

🟠 High  |  Microsoft Security Response Center  |  15 Jun 2025

CVE-2026-10846: Azure Query Response Verification Flaw

CVE-2026-10846 affects Azure with insufficient query-response verification, enabling potential DNS spoofing or traffic injection. Patch now.

🟠 High  |  Microsoft Security Response Center  |  13 Jun 2025

CVE-2026-11824: SQLite FTS5 Heap Buffer Overflow

CVE-2026-11824 is a heap buffer overflow in SQLite before 3.53.2 via FTS5. Learn the risk and remediation steps for Azure environments.

🟠 High  |  Microsoft Security Response Center  |  13 Jun 2025

CVE-2026-40034: gitoxide Command Injection via .gitmodules

CVE-2026-40034 affects gitoxide's gix-submodule crate, enabling command injection via partial .gitmodules overrides. Learn the risk and mitigation steps.

🟠 High  |  Microsoft Security Response Center  |  13 Jun 2025

CVE-2026-5222: Cargo Credential Leak Between Registries

CVE-2026-5222 allows Cargo to leak registry credentials to unintended endpoints. Learn the impact and how to protect your cloud build pipelines.

🟠 High  |  Microsoft Security Response Center  |  13 Jun 2025

CVE-2026-5223: Rust Crate Registry Cache Override Flaw

CVE-2026-5223 allows third-party Rust registries to override cached crate sources, posing a supply chain risk in cloud build pipelines.

🟠 High  |  Microsoft Security Response Center  |  13 Jun 2025

CVE-2026-5545: Azure HTTP Negotiate Connection Reuse Flaw

CVE-2026-5545 affects HTTP Negotiate connection reuse in Azure, potentially enabling session hijacking and unauthorised access. Patch now.

🟠 High  |  Microsoft Security Response Center  |  13 Jun 2025

CVE-2026-6429: Azure netrc Credential Leak via Proxy

CVE-2026-6429 exposes netrc credentials through reused proxy connections in Azure environments. Learn the impact and mitigation steps.

🟠 High  |  Microsoft Security Response Center  |  13 Jun 2025

CVE-2026-4873: Azure TLS Bypass via Connection Reuse

CVE-2026-4873 allows Azure connection reuse to silently bypass TLS requirements, risking data exposure in transit. Learn what architects should do.

🟠 High  |  Microsoft Security Response Center  |  13 Jun 2025

CVE-2026-6276: Azure Cookie Leak via Stale Host Config

CVE-2026-6276 affects Azure applications with stale custom cookie host settings, potentially leaking session cookies to unintended parties and enabling acc

🟠 High  |  Microsoft Security Response Center  |  13 Jun 2025

CVE-2026-6253: Azure Proxy Credentials Leak on Redirect

CVE-2026-6253 exposes proxy credentials during HTTP redirects in Azure environments. Learn the impact and how to protect your infrastructure.

🟠 High  |  Microsoft Security Response Center  |  13 Jun 2025

CVE-2026-34181: PKCS#12 PBMAC1 Weak HMAC Key Flaw

CVE-2026-34181 allows PKCS#12 files with weak PBMAC1 HMAC keys to be accepted, undermining certificate integrity in Azure environments.

🟠 High  |  Microsoft Security Response Center  |  13 Jun 2025

CVE-2026-42764: Azure QUIC NULL Pointer DoS Flaw

CVE-2026-42764 is a NULL pointer dereference in Azure's QUIC server packet handling that could allow remote denial-of-service attacks on exposed services.

🟠 High  |  Microsoft Security Response Center  |  13 Jun 2025

CVE-2026-45447: Heap Use-After-Free in PKCS7_verify

CVE-2026-45447 is a heap use-after-free flaw in PKCS7_verify() affecting Azure. Learn the risk and remediation steps for cloud security teams.

🟠 High  |  Microsoft Security Response Center  |  13 Jun 2025

CVE-2026-45445: AES-OCB IV Flaw in OpenSSL on Azure

CVE-2026-45445 causes AES-OCB IV to be ignored via EVP_Cipher(), breaking encryption integrity. Learn the impact and mitigation steps for Azure workloads.

🟠 High  |  Microsoft Security Response Center  |  13 Jun 2025

CVE-2026-47162: Vim netrw Code Injection Vulnerability

CVE-2026-47162 allows Vimscript code injection via crafted directory names in Vim's netrw plugin. Learn the impact and mitigation steps for Azure environme

🟠 High  |  Microsoft Security Response Center  |  13 Jun 2025

CVE-2026-47167: Vim Vimscript Code Injection Flaw

CVE-2026-47167 allows code injection via Vim's cucumber filetype plugin. Learn the impact and how cloud engineers should respond.

🟠 High  |  Microsoft Security Response Center  |  13 Jun 2025

CVE-2026-52860: Vim Arbitrary Code Execution Flaw

CVE-2026-52860 allows arbitrary code execution in Vim via Python omni-completion. Azure and Linux cloud users should patch immediately.

🟠 High  |  Microsoft Security Response Center  |  13 Jun 2025

CVE-2026-9149: Libsolv Heap Buffer Overflow in Azure

CVE-2026-9149 is a heap buffer overflow in libsolv triggered by a crafted .solv file. Learn the impact on Azure Linux workloads and how to remediate.

🟠 High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-9150: Libsolv Buffer Overflow in Azure

CVE-2026-9150 is a stack-based buffer overflow in libsolv's Debian metadata parser affecting SHA-384/SHA-512 checksums. Learn the Azure security impact and

🟠 High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-46598: Go SSH Agent Client Panic Flaw

CVE-2026-46598 allows pathological inputs to crash Go SSH agent clients, risking denial of service in Azure and other Go-based workloads.

🟠 High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-27136: XSS in golang.org/x/net/html on Azure

CVE-2026-27136 is an XSS flaw in Go's golang.org/x/net/html package. Azure-hosted Go apps may be at risk — patch now.

🟠 High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-42506: Go x/net/html Namespace Parsing Flaw

CVE-2026-42506 affects golang.org/x/net/html, causing incorrect handling of namespaced elements in foreign content. Azure Go apps may be at risk of XSS or

🟠 High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-25681: Go HTML Parsing Flaw in Azure

CVE-2026-25681 affects golang.org/x/net/html with incorrect DOCTYPE character reference handling. Azure workloads using Go may be at risk.

🟠 High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-39827: Go SSH Memory Leak DoS Vulnerability

CVE-2026-39827 is a memory leak in golang.org/x/crypto/ssh that enables Denial of Service by rejecting SSH channels. Azure workloads at risk.

🟠 High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-39835: Go SSH Library Server Panic Flaw

CVE-2026-39835 allows attackers to crash Go-based SSH servers without authentication via a panic in golang.org/x/crypto/ssh. Azure workloads at risk.

🟠 High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-25680: Go HTML Parser DoS Vulnerability

CVE-2026-25680 allows denial of service via malicious HTML in golang.org/x/net/html. Azure-hosted Go apps processing untrusted HTML should patch immediatel

🟠 High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-42502: Go HTML Parsing Flaw in Azure

CVE-2026-42502 affects golang.org/x/net/html with incorrect HTML element handling in foreign content. Azure workloads using Go may be at risk.

🟠 High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-39828: Go SSH Certificate Bypass in Azure

CVE-2026-39828 allows SSH certificate restriction bypass in golang.org/x/crypto/ssh. Azure-hosted Go workloads may be at risk — patch promptly.

🟠 High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-41140: Poetry Path Traversal in Python

CVE-2026-41140 exposes a path traversal flaw in Poetry's tar extraction on Python 3.10–3.11. Learn the risk and how to remediate.

🟠 High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2026-35414: OpenSSH Principals Auth Bypass

CVE-2026-35414 affects OpenSSH before 10.3, mishandling authorised_keys principals with CA comma characters — risking unauthorised SSH access on Azure VMs.

🟠 High  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2025-60876: BusyBox wget Header Injection Flaw

CVE-2025-60876 affects BusyBox wget ≤1.3.7, allowing HTTP header injection via control characters in URLs. Patch container images now.

🟠 High  |  Microsoft Security Response Center  |  3 Jun 2026

CVE-2026-25541: Integer Overflow in Rust BytesMut

CVE-2026-25541 exposes an integer overflow in the Rust bytes crate's BytesMut::reserve, risking memory corruption in Azure and cloud-native Rust apps.

🟠 High  |  Microsoft Security Response Center  |  3 Jun 2026

CVE-2024-7598: Azure Kubernetes Network Bypass Flaw

CVE-2024-7598 exposes a race condition in Kubernetes namespace termination that allows network restriction bypass in Azure environments. Patch now.

🟠 High  |  Microsoft Security Response Center  |  3 Jun 2026

CVE-2026-64205: Azure Linux Kernel i2c Driver Flaw

CVE-2026-64205 affects the Linux i2c-i801 kernel driver, causing hardware state machine corruption. Learn the impact on Azure Linux VMs and remediation ste

🟡 Medium  |  Microsoft Security Response Center  |  22 Jul 2024

CVE-2026-64187: Azure Linux XFS Log Recovery Flaw

CVE-2026-64187 affects XFS log recovery on Azure Linux workloads. Learn the risk, impact, and patching advice for cloud security teams.

🟡 Medium  |  Microsoft Security Response Center  |  22 Jul 2024

CVE-2026-38754: BusyBox Heap Overflow DoS on Azure

CVE-2026-38754 is a heap overflow in BusyBox v1.38.0 enabling denial of service attacks. Learn the impact for Azure container workloads and how to remediat

🟡 Medium  |  Microsoft Security Response Center  |  21 Jul 2024

CVE-2026-63828: AppArmor TCP Fast Open Bypass on Azure

CVE-2026-63828 allows AppArmor network policy bypass via TCP Fast Open sendmsg on Linux. Azure workloads and AKS nodes may be affected.

🟡 Medium  |  Microsoft Security Response Center  |  21 Jul 2024

CVE-2026-64146: Linux EROFS Metabuf Leak on Azure

CVE-2026-64146 is a Linux kernel EROFS memory leak in xattr initialisation affecting Azure VMs and containers. Learn what action to take.

🟡 Medium  |  Microsoft Security Response Center  |  21 Jul 2024

CVE-2026-63882 Azure Linux AMD GPU NULL Pointer Fix

CVE-2026-63882 is a NULL pointer bug in the Linux AMD GPU kernel driver affecting Azure GPU VMs. Learn the impact and patching steps.

🟡 Medium  |  Microsoft Security Response Center  |  21 Jul 2024

CVE-2026-63940: KVM SEV Port I/O Flaw on Azure

CVE-2026-63940 affects KVM's AMD SEV implementation via zero-length Port I/O requests. Learn the impact for Azure confidential computing workloads.

🟡 Medium  |  Microsoft Security Response Center  |  21 Jul 2024

CVE-2026-64097 AMD Display Driver Linux Kernel Flaw

CVE-2026-64097 affects the AMD display driver in the Linux kernel. Learn the security impact and mitigation steps for Azure cloud environments.

🟡 Medium  |  Microsoft Security Response Center  |  21 Jul 2024

CVE-2026-64133: Linux ALSA OOB Fix in Azure

CVE-2026-64133 fixes an out-of-bounds array access in the Linux ALSA HPI audio driver. Azure users running Linux VMs should review and apply kernel patches

🟡 Medium  |  Microsoft Security Response Center  |  21 Jul 2024

CVE-2026-50527 .NET Framework DoS Vulnerability

Microsoft updates product info for CVE-2026-50527, a .NET Framework Denial of Service flaw. Azure architects should verify affected versions and patching s

🟡 Medium  |  Microsoft Security Response Center  |  20 Jul 2024

CVE-2026-50659: .NET Spoofing Vulnerability | Azure

CVE-2026-50659 is a .NET spoofing vulnerability. Microsoft has updated product coverage details — check your .NET patch status now.

🟡 Medium  |  Microsoft Security Response Center  |  20 Jul 2024

CVE-2026-53386: Linux Kernel ADC Driver Bounds Check Fix

CVE-2026-53386 addresses a missing bounds check in the Linux kernel TI ADS1298 ADC driver, affecting Azure Linux environments. Patch promptly.

🟡 Medium  |  Microsoft Security Response Center  |  20 Jul 2024

CVE-2026-59886: pyasn1 DoS Flaw Affects Azure

CVE-2026-59886 exposes a denial-of-service risk in pyasn1 via uncontrolled resource consumption. Azure users should patch promptly.

🟡 Medium  |  Microsoft Security Response Center  |  17 Jul 2024

CVE-2026-50341 Windows NTFS Info Disclosure Vulnerability

CVE-2026-50341 is a Windows NTFS information disclosure vulnerability. Latest advisory update is acknowledgment-only — no new patches required.

🟡 Medium  |  Microsoft Security Response Center  |  15 Jul 2024

CVE-2026-42505: Encrypted Client Hello Privacy Leak in Go TL

CVE-2026-42505 exposes a privacy leak in Go's crypto/tls Encrypted Client Hello implementation, potentially revealing connection destinations on Azure work

🟡 Medium  |  Microsoft Security Response Center  |  15 Jul 2024

CVE-2026-34346: Windows WinSock Info Disclosure

CVE-2026-34346 affects the Windows AFD WinSock driver, exposing sensitive data in cleartext to local attackers. Learn the impact and remediation steps.

🟡 Medium  |  Microsoft Security Response Center  |  14 Jul 2024

CVE-2026-34349 Windows Media Info Disclosure Flaw

CVE-2026-34349 is a Windows Media information disclosure vulnerability allowing local attackers to access sensitive data. Patch Windows systems promptly.

🟡 Medium  |  Microsoft Security Response Center  |  14 Jul 2024

CVE-2026-49165: Windows App Store Info Disclosure

CVE-2026-49165 is a Windows App Store information disclosure flaw allowing local attackers to access sensitive data via an uninitialised resource.

🟡 Medium  |  Microsoft Security Response Center  |  14 Jul 2024

CVE-2025-38096: Azure Linux iwlwifi Kernel Driver Flaw

CVE-2025-38096 affects the Linux kernel iwlwifi Wi-Fi driver on Azure. Learn what cloud architects need to know and how to respond.

🟡 Medium  |  Microsoft Security Response Center  |  13 Jul 2024

CVE-2026-45489: Microsoft Edge Spoofing Vulnerability

CVE-2026-45489 is a spoofing flaw in Microsoft Edge (Chromium-based). Latest update adds CWE classification only — no new patch required.

🟡 Medium  |  Microsoft Security Response Center  |  12 Jul 2024

CVE-2026-56289: GNU patch Loop Flaw Affects Azure

CVE-2026-56289 is a denial-of-service vulnerability in GNU patch affecting Azure workloads. Learn the risks and remediation steps for cloud environments.

🟡 Medium  |  Microsoft Security Response Center  |  10 Jul 2024

CVE-2025-23131: Linux Kernel DLM NULL Pointer Flaw on Azure

CVE-2025-23131 affects the Linux kernel DLM subsystem, risking kernel crashes via NULL pointer dereference. Azure Linux VM users should patch promptly.

🟡 Medium  |  Microsoft Security Response Center  |  9 Jul 2024

CVE-2026-59996: OpenSSH scp Path Traversal on Azure

CVE-2026-59996 affects scp in OpenSSH before 10.4, allowing files to be written to parent directories during remote-to-remote copies. Azure workloads may b

🟡 Medium  |  Microsoft Security Response Center  |  9 Jul 2024

CVE-2026-59997: OpenSSH SFTP Argument Limit Flaw

CVE-2026-59997 affects OpenSSH before 10.4: internal-sftp ignores arguments beyond the 9th, potentially bypassing security controls on SFTP connections.

🟡 Medium  |  Microsoft Security Response Center  |  9 Jul 2024

CVE-2026-53223: Azure Linux Kernel Network Flaw

CVE-2026-53223 affects Linux kernel timestamp cmsg handling on Azure. Learn the risk and patching steps for cloud security architects.

🟡 Medium  |  Microsoft Security Response Center  |  4 Jul 2024

CVE-2026-13933: Edge Chromium Password Policy Flaw

CVE-2026-13933 affects Microsoft Edge via a Chromium flaw in password policy enforcement. Update Edge immediately to protect stored credentials.

🟡 Medium  |  Microsoft Security Response Center  |  3 Jul 2024

CVE-2026-55945: Microsoft Edge Information Disclosure

CVE-2026-55945 is a race condition flaw in Microsoft Edge (Chromium-based) enabling local information disclosure. Patch now to protect sensitive data.

🟡 Medium  |  Microsoft Security Response Center  |  3 Jul 2024

CVE-2026-58522: Edge for Android Info Disclosure

CVE-2026-58522 is a path traversal flaw in Microsoft Edge for Android enabling local information disclosure. Patch via MDM now.

🟡 Medium  |  Microsoft Security Response Center  |  3 Jul 2024

CVE-2026-58013: GLib Buffer Over-Read in Azure

CVE-2026-58013 is a GLib buffer over-read vulnerability in giochannel.c affecting Azure Linux workloads. Learn the impact and remediation steps.

🟡 Medium  |  Microsoft Security Response Center  |  1 Jul 2024

CVE-2026-58011: GLib Out-of-Bounds Read in Azure

CVE-2026-58011 is a GLib out-of-bounds read flaw in date/time parsing, affecting Azure and Linux workloads. Learn the risk and remediation steps.

🟡 Medium  |  Microsoft Security Response Center  |  1 Jul 2024

CVE-2026-53325: Azure Linux Kernel AGP AMD64 Bug Fix

CVE-2026-53325 fixes broken error propagation in the Linux kernel AGP AMD64 driver. Azure users on Linux VMs should review and apply patches promptly.

🟡 Medium  |  Microsoft Security Response Center  |  30 Jun 2024

CVE-2026-41991: GNU gzip Predictable Temp File Flaw

CVE-2026-41991 affects GNU gzip with predictable temp files, risking symlink attacks on Azure Linux workloads. Patch and audit privileged gzip usage now.

🟡 Medium  |  Microsoft Security Response Center  |  30 Jun 2024

CVE-2026-23207: Linux SPI Driver Flaw in Azure

CVE-2026-23207 affects the Linux kernel Tegra210 SPI driver with an unprotected IRQ handler check. Review Azure VM and AKS node patching status now.

🟡 Medium  |  Microsoft Security Response Center  |  28 Jun 2024

CVE-2025-21870: Linux Kernel SOF ALH Copier Flaw

CVE-2025-21870 affects the Linux kernel SOF IPC4 audio topology component. Learn the impact for Azure Linux VMs and how to remediate.

🟡 Medium  |  Microsoft Security Response Center  |  28 Jun 2024

CVE-2025-21888: Azure RDMA/mlx5 Kernel Fix

CVE-2025-21888 fixes a Linux kernel WARN in the RDMA/mlx5 driver affecting Azure RDMA-capable VMs. Learn what action architects should take.

🟡 Medium  |  Microsoft Security Response Center  |  28 Jun 2024

CVE-2026-23214: Linux btrfs Read-Only Bypass on Azure

CVE-2026-23214 affects the Linux btrfs driver, allowing write transactions on read-only filesystems. Learn the Azure impact and remediation steps.

🟡 Medium  |  Microsoft Security Response Center  |  28 Jun 2024

CVE-2025-71225: Linux RAID sysfs Race Condition on Azure

CVE-2025-71225 is a Linux kernel RAID race condition affecting Azure Linux VMs. Learn the impact and recommended actions for cloud security teams.

🟡 Medium  |  Microsoft Security Response Center  |  28 Jun 2024

CVE-2026-23213: AMD GPU MMIO Flaw in Azure VMs

CVE-2026-23213 exposes a kernel-level AMD GPU driver flaw affecting MMIO access during SMU reset — patch Azure GPU workloads promptly.

🟡 Medium  |  Microsoft Security Response Center  |  28 Jun 2024

CVE-2025-40213: Azure Linux Kernel Bluetooth Crash Fix

CVE-2025-40213 affects the Linux kernel Bluetooth MGMT subsystem, causing crashes in mesh sync functions. Azure workloads running vulnerable kernels should

🟡 Medium  |  Microsoft Security Response Center  |  28 Jun 2024

CVE-2025-21885: Azure Linux Kernel RDMA bnxt_re Flaw

CVE-2025-21885 affects the Linux kernel RDMA bnxt_re driver on Azure. Learn the security impact and what cloud architects should do now.

🟡 Medium  |  Microsoft Security Response Center  |  28 Jun 2024

CVE-2025-21892: Azure RDMA mlx5 UMR QP Recovery Flaw

CVE-2025-21892 fixes a recovery flow bug in the Linux RDMA/mlx5 UMR Queue Pair, affecting Azure RDMA-enabled workloads. Patch now to prevent instability.

🟡 Medium  |  Microsoft Security Response Center  |  28 Jun 2024

CVE-2025-40146: Azure Linux Kernel blk-mq Deadlock Fix

CVE-2025-40146 fixes a potential deadlock in the Linux kernel blk-mq subsystem on Azure. Learn the impact and patching steps for cloud engineers.

🟡 Medium  |  Microsoft Security Response Center  |  28 Jun 2024

CVE-2025-21833: Linux IOMMU VT-d NULL Pointer Flaw

CVE-2025-21833 affects the Linux kernel's Intel VT-d IOMMU driver. Learn the security impact for Azure and cloud VM workloads and recommended mitigations.

🟡 Medium  |  Microsoft Security Response Center  |  28 Jun 2024

CVE-2024-58089: btrfs Race Condition Fix on Azure

CVE-2024-58089 fixes a double accounting race condition in the btrfs kernel driver affecting Linux workloads on Azure. Learn what action to take.

🟡 Medium  |  Microsoft Security Response Center  |  28 Jun 2024

CVE-2026-13034: Chromium Password Flaw in Microsoft Edge

CVE-2026-13034 affects Chromium's password implementation, impacting Microsoft Edge. Learn what cloud security teams should do to mitigate the risk.

🟡 Medium  |  Microsoft Security Response Center  |  27 Jun 2024

CVE-2026-13022: Chromium Autofill Flaw Affects Edge

CVE-2026-13022 is a Chromium Autofill implementation flaw affecting Microsoft Edge. Learn the security impact and how to protect your organisation.

🟡 Medium  |  Microsoft Security Response Center  |  27 Jun 2024

CVE-2026-45930: Azure Linux Kernel MCTP Memory Flaw

CVE-2026-45930 affects the Linux kernel MCTP subsystem on Azure. Uninitialised netlink responses may expose kernel memory. Patch now.

🟡 Medium  |  Microsoft Security Response Center  |  26 Jun 2024

CVE-2025-68296: Linux Kernel Race Condition in fbcon & DRM

CVE-2025-68296 is a Linux kernel race condition in fbcon, DRM, and vga_switcheroo. Azure Linux VM and AKS users should patch promptly.

🟡 Medium  |  Microsoft Security Response Center  |  26 Jun 2024

CVE-2026-4367 libxpm DoS Flaw Affects Azure Workloads

CVE-2026-4367 is a denial-of-service flaw in libxpm triggered by malformed XPM files. Azure workloads with libxpm dependencies should be patched promptly.

🟡 Medium  |  Microsoft Security Response Center  |  25 Jun 2024

CVE-2026-46140 Linux Bluetooth btmtk Kernel Flaw

CVE-2026-46140 affects the Linux kernel Bluetooth btmtk driver. Learn the security impact for Azure workloads and what architects should do.

🟡 Medium  |  Microsoft Security Response Center  |  25 Jun 2024

CVE-2026-46285 Linux Kernel Use-After-Free in Azure

CVE-2026-46285 is a Linux kernel use-after-free flaw in the docg3 MTD driver. Learn the impact on Azure workloads and recommended remediation steps.

🟡 Medium  |  Microsoft Security Response Center  |  24 Jun 2024

CVE-2025-5791: Azure Root User Group Listing Flaw

CVE-2025-5791 causes 'root' to be incorrectly appended to Azure group listings, risking information disclosure and potential reconnaissance by attackers.

🟡 Medium  |  Microsoft Security Response Center  |  20 Jun 2024

CVE-2026-44821: Microsoft Office for Mac Info Disclosure

CVE-2026-44821 affects Microsoft Office for Mac, enabling information disclosure. Apply Microsoft's security update immediately to protect affected endpoin

🟡 Medium  |  Microsoft Security Response Center  |  19 Jun 2024

CVE-2026-45466: Microsoft Word Info Disclosure on Mac

Microsoft has patched CVE-2026-45466, an information disclosure flaw in Microsoft Word for Mac. Update Office for Mac now to protect sensitive data.

🟡 Medium  |  Microsoft Security Response Center  |  19 Jun 2024

CVE-2026-45485: Microsoft Office for Mac Info Disclosure

CVE-2026-45485 affects Microsoft Office for Mac, enabling information disclosure. Learn what security teams should do to patch and protect their environmen

🟡 Medium  |  Microsoft Security Response Center  |  19 Jun 2024

CVE-2026-12087: Perl Socket Heap Read Vulnerability

CVE-2026-12087 affects Perl Socket versions before 2.041 with an out-of-bounds heap read. Update now to prevent potential information disclosure.

🟡 Medium  |  Microsoft Security Response Center  |  19 Jun 2024

CVE-2026-44967: OpenTelemetry-cpp Unbounded HTTP Response Fl

CVE-2026-44967 affects opentelemetry-cpp OTLP HTTP exporters, allowing unbounded HTTP responses that could cause DoS. Azure users should patch promptly.

🟡 Medium  |  Microsoft Security Response Center  |  19 Jun 2024

CVE-2026-46293: Linux Kernel Out-of-Bounds Flaw on Azure

CVE-2026-46293 is a Linux kernel out-of-bounds access bug in the Microchip clock driver. Learn the impact for Azure workloads and how to remediate.

🟡 Medium  |  Microsoft Security Response Center  |  18 Jun 2024

CVE-2026-46291: Linux CAAM HMAC Key Leak on Azure

CVE-2026-46291 exposes HMAC key material via unguarded hex dumps in the Linux kernel CAAM driver. Azure Linux VM users should patch promptly.

🟡 Medium  |  Microsoft Security Response Center  |  18 Jun 2024

CVE-2026-46292: Linux Kernel pmdomain Flaw in Azure

CVE-2026-46292 is a Linux kernel pmdomain/genpd vulnerability affecting Azure Linux VMs. Learn the security impact and recommended mitigations.

🟡 Medium  |  Microsoft Security Response Center  |  18 Jun 2024

CVE-2026-43308: Linux btrfs Kernel Panic Fix – Azure

CVE-2026-43308 fixes a Linux kernel btrfs bug that could cause a kernel panic on Azure VMs. Learn the impact and recommended patching steps.

🟡 Medium  |  Microsoft Security Response Center  |  18 Jun 2024

CVE-2025-71072: Azure Linux Kernel shmem Rename Fix

CVE-2025-71072 fixes a Linux kernel shmem rename failure recovery bug affecting Azure workloads. Learn the risk and how to patch.

🟡 Medium  |  Microsoft Security Response Center  |  18 Jun 2024

CVE-2025-71073: Azure Linux Kernel lkkbd Driver Flaw

CVE-2025-71073 is a Linux kernel lkkbd driver use-after-free vulnerability affecting Azure Linux workloads. Patch promptly to prevent memory corruption ris

🟡 Medium  |  Microsoft Security Response Center  |  18 Jun 2024

CVE-2026-42766: NULL Dereference in CMS Decryption

CVE-2026-42766 is a NULL dereference flaw in password-based CMS decryption that could allow denial of service via malformed encrypted input on Azure.

🟡 Medium  |  Microsoft Security Response Center  |  18 Jun 2024

CVE-2026-45602 Windows DHCP Tampering Vulnerability

CVE-2026-45602 covers a Windows DHCP tampering vulnerability. Latest update is a CWE correction only — no patch or severity changes required.

🟡 Medium  |  Microsoft Security Response Center  |  16 Jun 2024

CVE-2023-5678 OpenSSL DH DoS Flaw Affects Azure

CVE-2023-5678 is an OpenSSL denial-of-service vulnerability affecting Azure. Large DH Q parameters cause excessive CPU use. Patch now.

🟡 Medium  |  Microsoft Security Response Center  |  13 Jun 2024

CVE-2026-52859: Vim Out-of-Bounds Read on Azure

CVE-2026-52859 is an out-of-bounds read flaw in Vim's terminal snapshot feature, affecting Azure VMs and containers running Vim. Patch and audit now.

🟡 Medium  |  Microsoft Security Response Center  |  13 Jun 2024

CVE-2026-43964: Postfix Buffer Over-Read Crash Flaw

CVE-2026-43964 affects Postfix mail servers, causing process crashes via malformed status codes. Learn the impact and how to patch on Azure infrastructure.

🟡 Medium  |  Microsoft Security Response Center  |  4 Jun 2026

CVE-2025-29923: go-redis Out-of-Order Response Flaw

CVE-2025-29923 in go-redis can cause out-of-order responses when CLIENT SETINFO times out. Learn the risk and remediation steps.

🟡 Medium  |  Microsoft Security Response Center  |  3 Jun 2026

CVE-2020-8561: Kubernetes Webhook Redirect Flaw in AKS

CVE-2020-8561 allows webhook redirect abuse in kube-apiserver, enabling SSRF via Kubernetes admission webhooks. Affects AKS and self-managed clusters.

🟡 Medium  |  Microsoft Security Response Center  |  3 Jun 2026

CVE-2025-1149: GNU Binutils ld Memory Leak – Azure

CVE-2025-1149 is a memory leak in GNU Binutils ld (xmalloc.c). Learn about the Azure security impact and recommended patching guidance.

🟢 Low  |  Microsoft Security Response Center  |  4 Jun 2026

📬 Stay Informed

Get daily cloud security advisories delivered to your inbox.

Free. No spam. Unsubscribe anytime. View subscription options