🟠 High | Source: Microsoft Security Response Center
CVE-2026-16461 is a stack buffer overflow vulnerability in rpcbind, specifically within the rpcinfo rpcbdump() function when formatting version lists in short mode. This type of memory corruption flaw can potentially allow an attacker to crash the service or execute arbitrary code. It is relevant to Azure environments where rpcbind is running on Linux-based virtual machines or container workloads.
Security Architect’s Take: Audit Azure VM and container workloads for exposed rpcbind services and apply vendor patches as soon as they become available; in the interim, restrict network access to rpcbind (port 111) via NSGs and firewall rules to limit the attack surface.
Original advisory: CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting