<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cve-2026-6276 on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/cve-2026-6276/</link><description>Recent content in Cve-2026-6276 on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Fri, 13 Jun 2025 08:41:47 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/cve-2026-6276/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-6276: Azure Cookie Leak via Stale Host Config</title><link>https://zxcloudsecurity.co.uk/posts/azure-stale-custom-cookie-host-cookie-leak-cve-2026-6276/</link><pubDate>Sat, 13 Jun 2026 08:41:47 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/azure-stale-custom-cookie-host-cookie-leak-cve-2026-6276/</guid><description>CVE-2026-6276 affects Azure applications with stale custom cookie host settings, potentially leaking session cookies to unintended parties and enabling acc</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-6276">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-6276 is a vulnerability in Azure where a stale custom cookie host configuration can cause session cookies to be leaked to unintended parties. This could allow an attacker to intercept or reuse authentication cookies, potentially gaining unauthorised access to user sessions or sensitive data. It matters because cookie leakage in cloud-hosted applications can lead to account takeover without requiring credentials.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review any Azure-hosted applications using custom cookie domain configurations and ensure cookie host settings are kept current and accurate — stale or misconfigured host entries should be audited and corrected promptly. Apply any available Microsoft patch and consider enforcing the Secure and SameSite=Strict cookie attributes as a defence-in-depth measure.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-6276">CVE-2026-6276 stale custom cookie host causes cookie leak</a></p>
]]></content:encoded></item></channel></rss>