Azure security advisories
46 threat alerts tracking vulnerabilities and security advisories that affect Azure products.
Vulnios monitors Azure CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent Azure security news in one place, or click into an individual alert for full detail.
CVE-2026-62836 Azure SQL Managed Instance Elevation of Privilege Vulnerability
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-62836CVE-2026-50481 Azure Active Directory Elevation of Privilege Vulnerability
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-50481CVE-2026-65806 Azure CycleCloud Information Disclosure Vulnerability
Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.
criticalCVE-2026-65806CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-57104CVE-2026-70340 Azure CycleCloud Elevation of Privilege Vulnerability
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-70340CVE-2026-47299 Azure Monitor Agent Elevation of Privilege Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-47299CVE-2026-58275 Azure DNS Elevation of Privilege Vulnerability
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-58275CVE-2026-35425 Azure API Management (APIM) Remote Code Execution Vulnerability
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
criticalCVE-2026-35425CVE-2026-58630 Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-58630CVE-2026-56167 Azure AI Search Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-56167CVE-2026-62825 Azure Key Vault Elevation of Privilege Vulnerability
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-62825CVE-2026-50338 Azure Spring Apps Elevation of Privilege Vulnerability
Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-50338CVE-2026-47632 Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability
Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
criticalCVE-2026-47632CVE-2026-50652 Azure Active Directory Denial of Service Vulnerability
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
criticalCVE-2026-50652CVE-2026-50653 Azure Active Directory Denial of Service Vulnerability
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
criticalCVE-2026-50653CVE-2026-58279 Azure CycleCloud Elevation of Privilege Vulnerability
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-58279CVE-2026-57969 Azure CycleCloud Elevation of Privilege Vulnerability
Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-57969CVE-2026-45499 Azure OpenAI Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-45499Gardyn IoT Hub
View CSAF Summary Successful exploitation of these vulnerabilities could allow unauthenticated users to access and control IoT Hub managed devices. The following versions of Gardyn IoT Hub are affecte
criticalCVE-2026-13768Massive Password Spray Campaign Targeting Azure CLI
Hackers were seen making over 81 million login attempts originating from systems associated with hosting provider LSHIY. The post Massive Password Spray Campaign Targeting Azure CLI appeared first on
criticalCVE-2026-45480 Azure Active Directory Elevation of Privilege Vulnerability
Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-45480CVE-2026-32174 Azure Bot Service Elevation of Privilege Vulnerability
Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-32174CVE-2026-41098 Azure Stack Edge Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.
criticalCVE-2026-41098CVE-2026-47643 Azure Stack Edge Remote Code Execution Vulnerability
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.
criticalCVE-2026-47643CVE-2026-48567 Azure HorizonDB Elevation of Privilege Vulnerability
Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-48567ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More
The Hacker News published an news on "ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More". Topic areas: zero-day, malware, ransomware, data-breach. Pu
criticalCVE-2026-42822 Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability
Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-42822CVE-2026-33833 Azure Machine Learning Notebook Spoofing Vulnerability
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.
criticalCVE-2026-33833CVE-2026-40381 Azure Connected Machine Agent Elevation of Privilege Vulnerability
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
criticalCVE-2026-40381CVE-2026-32204 Azure Monitor Agent Elevation of Privilege Vulnerability
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
criticalCVE-2026-32204CVE-2026-42823 Azure Logic Apps Elevation of Privilege Vulnerability
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-42823CVE-2026-33117 Azure SDK for Java Security Feature Bypass Vulnerability
Improper authentication in Azure SDK allows an unauthorized attacker to bypass a security feature over a network.
criticalCVE-2026-33117CVE-2026-41086 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-41086CVE-2026-42830 Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability
Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
criticalCVE-2026-42830CVE-2026-35435 Azure AI Foundry Elevation of Privilege Vulnerability
Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-35435CVE-2026-35428 Azure Cloud Shell Spoofing Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network.
criticalCVE-2026-35428CVE-2026-41105 Azure Monitor Action Group Notification System Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-41105CVE-2026-42826 Azure DevOps Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.
criticalCVE-2026-42826CVE-2026-32207 Azure Machine Learning Notebook Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.
criticalCVE-2026-32207CVE-2026-42151 Prometheus Azure AD remote write OAuth client secret exposed via config API
Microsoft Security Response Center published an advisory on "CVE-2026-42151 Prometheus Azure AD remote write OAuth client secret exposed via config API". Topic areas: microsoft, windows, azure, patch.
criticalCVE-2026-42151ConsentFix v3 attacks target Azure with automated OAuth abuse
ConsentFix v3 attacks target Azure with automated OAuth abuse
criticalABB Ability OPTIMAX
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to bypass user authentication on OPTIMAX installations that make use of the Azure Active Directory Single-Sign O
criticalCVE-2025-14510CVE-2026-21515 Azure IoT Central Elevation of Privilege Vulnerability
Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-21515CVE-2026-32168 Azure Monitor Agent Elevation of Privilege Vulnerability
Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
criticalCVE-2026-32168CVE-2026-32171 Azure Logic Apps Elevation of Privilege Vulnerability
Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-32171CVE-2026-32192 Azure Monitor Agent Elevation of Privilege Vulnerability
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
criticalCVE-2026-32192
Track Azure exposure across your environment
Vulnios automatically cross-references your asset inventory against new Azure CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan