Description
Multiple vulnerabilities were found in Microsoft Azure. Malicious users can exploit these vulnerabilities to spoof user interface, bypass security restrictions, gain privileges.
Below is a complete list of vulnerabilities:
- A spoofing vulnerability in Azure Machine Learning Notebook can be exploited remotely to spoof user interface.
- An elevation of privilege vulnerability in Azure Logic Apps can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Azure Monitor Agent Metrics Extension can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Azure Monitor Agent can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Windows Admin Center in Azure Portal can be exploited remotely to gain privileges.
- A security feature bypass vulnerability in Azure SDK for Java can be exploited remotely to bypass security restrictions.
- An elevation of privilege vulnerability in Microsoft SSO Plugin for Jira & Confluence can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Azure Connected Machine Agent can be exploited remotely to gain privileges.
Original advisories
- CVE-2026-42823
- CVE-2026-42830
- CVE-2026-32204
- CVE-2026-41086
- CVE-2026-33117
- CVE-2026-41103
- CVE-2026-40381
Exploitation
Related products
- Microsoft-Windows
- Microsoft-Azure
- Azure-Connected-Machine-Agent
- Azure-Monitor
- Arc-Enabled-Servers-Azure-Connected-Machine-Agent
- Azure-Monitor-Agent
CVE list
- CVE-2026-32204 critical
- CVE-2026-33117 critical
- CVE-2026-33833 critical
- CVE-2026-40381 critical
- CVE-2026-41086 critical
- CVE-2026-41103 critical
- CVE-2026-42823 critical
- CVE-2026-42830 high
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!