Description
Multiple vulnerabilities were found in Microsoft Azure. Malicious users can exploit these vulnerabilities to spoof user interface, bypass security restrictions, gain privileges, obtain sensitive information.
Below is a complete list of vulnerabilities:
- A spoofing vulnerability in Microsoft Entra ID Entitlement Management can be exploited remotely to spoof user interface.
- An elevation of privilege vulnerability in Microsoft Partner Center can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Azure IoT Central can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Microsoft Purview eDiscovery can be exploited remotely to gain privileges.
Original advisories
Exploitation
Related products
CVE list
- CVE-2026-24303 critical
- CVE-2026-26150 critical
- CVE-2026-35431 critical
- CVE-2026-21515 critical
KB list
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!