Azure security advisories
60 threat alerts tracking vulnerabilities and security advisories that affect Azure products.
Vulnios monitors Azure CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent Azure security news in one place, or click into an individual alert for full detail.
CVE-2026-70352 Azure AI Language Elevation of Privilege Vulnerability
Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-70352CVE-2026-69857 Azure Cosmos DB Spoofing Vulnerability
Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.
criticalCVE-2026-69857SANS Internet Storm Center Advisory — Sep 1, 2026
SANS Internet Storm Center published an research on "SANS Internet Storm Center Advisory — Sep 1, 2026". Topic areas: sans, isc, incident, daily-summary. Published September 1, 2026. See the original
criticalSANS Internet Storm Center Advisory — Aug 26, 2026
A common thing that folks should "worry" about in Entra (or any platform really) is "who has rights to administer"?  Who can delete or change key things, or modify them
criticalCVE-2026-66800 Azure Data Factory Information Disclosure Vulnerability
Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
criticalCVE-2026-66800CVE-2026-69555 Azure Arc Elevation of Privilege Vulnerability
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-69555CVE-2026-68782 Azure SQL Database Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-68782CVE-2026-69519 Azure Stack HCI Information Disclosure Vulnerability
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
criticalCVE-2026-69519CVE-2026-69502 Azure SQL Database Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-69502CVE-2026-69543 Azure Virtual Machines Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-69543CVE-2026-68789 Azure SQL Database Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-68789CVE-2026-66309 Azure SQL Database Elevation of Privilege Vulnerability
Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-66309CVE-2026-69400 Azure Logic Apps Elevation of Privilege Vulnerability
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-69400CVE-2026-65816 Azure Arc Elevation of Privilege Vulnerability
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-65816CVE-2026-62834 Azure Data Factory Elevation of Privilege Vulnerability
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-62834CVE-2026-69419 Azure Data Manager for Energy Remote Code Execution Vulnerability
Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.
criticalCVE-2026-69419CVE-2026-70340 Azure CycleCloud Elevation of Privilege Vulnerability
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-70340CVE-2026-57104 Azure Storage Explorer Elevation of Privilege Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Storage Explorer allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-57104CVE-2026-65806 Azure CycleCloud Information Disclosure Vulnerability
Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.
criticalCVE-2026-65806CVE-2026-47299 Azure Monitor Agent Elevation of Privilege Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-47299CVE-2026-62830 Azure SRE Agent Elevation of Privilege Vulnerability
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-62830CVE-2026-68823 Azure Confidential Ledger Remote Code Execution Vulnerability
Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.
criticalCVE-2026-68823CVE-2026-50515 Azure Service Bus Remote Code Execution Vulnerability
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
criticalCVE-2026-50515CVE-2026-56162 Azure SQL Database Elevation of Privilege Vulnerability
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-56162CVE-2026-56161 Azure Logic Apps Information Disclosure Vulnerability
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.
criticalCVE-2026-56161CVE-2026-62869 Azure Entra ID Spoofing Vulnerability
Insufficient verification of data authenticity in Azure Entra ID allows an authorized attacker to perform spoofing over a network.
criticalCVE-2026-62869CVE-2026-63522 Azure SQL Database Elevation of Privilege Vulnerability
Incorrect permission assignment for critical resource in Azure SQL Database allows an authorized attacker to elevate privileges locally.
criticalCVE-2026-63522CVE-2026-50481 Azure Active Directory Elevation of Privilege Vulnerability
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-50481CVE-2026-62836 Azure SQL Managed Instance Elevation of Privilege Vulnerability
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-62836CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
criticalCVE-2026-66803CVE-2026-58630 Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-58630CVE-2026-56167 Azure AI Search Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-56167CVE-2026-58275 Azure DNS Elevation of Privilege Vulnerability
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-58275CVE-2026-62825 Azure Key Vault Elevation of Privilege Vulnerability
Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-62825CVE-2026-35425 Azure API Management (APIM) Remote Code Execution Vulnerability
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
criticalCVE-2026-35425CVE-2026-58279 Azure CycleCloud Elevation of Privilege Vulnerability
Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-58279CVE-2026-50653 Azure Active Directory Denial of Service Vulnerability
Loop with unreachable exit condition ('infinite loop') in Azure Active Directory allows an unauthorized attacker to deny service over a network.
criticalCVE-2026-50653CVE-2026-47632 Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability
Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.
criticalCVE-2026-47632CVE-2026-50338 Azure Spring Apps Elevation of Privilege Vulnerability
Improper authentication in Azure Spring Apps allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-50338CVE-2026-57969 Azure CycleCloud Elevation of Privilege Vulnerability
Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-57969CVE-2026-50652 Azure Active Directory Denial of Service Vulnerability
Deserialization of untrusted data in Azure Active Directory allows an unauthorized attacker to deny service over a network.
criticalCVE-2026-50652CVE-2026-45499 Azure OpenAI Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-45499CVE-2026-32174 Azure Bot Service Elevation of Privilege Vulnerability
Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-32174CVE-2026-45480 Azure Active Directory Elevation of Privilege Vulnerability
Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-45480CVE-2026-41098 Azure Stack Edge Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.
criticalCVE-2026-41098CVE-2026-47643 Azure Stack Edge Remote Code Execution Vulnerability
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.
criticalCVE-2026-47643CVE-2026-48567 Azure HorizonDB Elevation of Privilege Vulnerability
Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-48567CVE-2026-42822 Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability
Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-42822CVE-2026-33833 Azure Machine Learning Notebook Spoofing Vulnerability
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.
criticalCVE-2026-33833CVE-2026-32204 Azure Monitor Agent Elevation of Privilege Vulnerability
External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
criticalCVE-2026-32204CVE-2026-41086 Windows Admin Center in Azure Portal Elevation of Privilege Vulnerability
Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-41086CVE-2026-33117 Azure SDK for Java Security Feature Bypass Vulnerability
Improper authentication in Azure SDK allows an unauthorized attacker to bypass a security feature over a network.
criticalCVE-2026-33117CVE-2026-40381 Azure Connected Machine Agent Elevation of Privilege Vulnerability
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
criticalCVE-2026-40381CVE-2026-42823 Azure Logic Apps Elevation of Privilege Vulnerability
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-42823CVE-2026-42830 Azure Monitor Agent Metrics Extension Elevation of Privilege Vulnerability
Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
criticalCVE-2026-42830CVE-2026-35435 Azure AI Foundry Elevation of Privilege Vulnerability
Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.
criticalCVE-2026-35435CVE-2026-32207 Azure Machine Learning Notebook Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.
criticalCVE-2026-32207CVE-2026-41105 Azure Monitor Action Group Notification System Elevation of Privilege Vulnerability
Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network.
criticalCVE-2026-41105CVE-2026-42826 Azure DevOps Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.
criticalCVE-2026-42826CVE-2026-35428 Azure Cloud Shell Spoofing Vulnerability
Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network.
criticalCVE-2026-35428
Showing the 60 most recent. Older alerts are archived but still reachable via search and the main feed.
Track Azure exposure across your environment
Vulnios automatically cross-references your asset inventory against new Azure CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan