Description
Multiple vulnerabilities were found in Microsoft Azure. Malicious users can exploit these vulnerabilities to bypass security restrictions, execute arbitrary code, gain privileges, obtain sensitive information.
Below is a complete list of vulnerabilities:
- A remote code execution vulnerability in Azure API Management (APIM) can be exploited remotely to execute arbitrary code.
- An information disclosure vulnerability in Microsoft Graph can be exploited remotely to obtain sensitive information.
- An elevation of privilege vulnerability in Azure Red Hat OpenShift (ARO) can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Microsoft Azure Kubernetes Service can be exploited remotely to gain privileges.
- A remote code execution vulnerability in Microsoft Account can be exploited remotely to execute arbitrary code.
- An elevation of privilege vulnerability in Azure AI Search can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Data Quality can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Azure App Service on Azure Stack Hub can be exploited remotely to gain privileges.
- An information disclosure vulnerability in Azure Portal can be exploited remotely to obtain sensitive information.
Original advisories
- CVE-2026-49159
- CVE-2026-56160
- CVE-2026-56163
- CVE-2026-56165
- CVE-2026-56167
- CVE-2026-57106
- CVE-2026-58630
- CVE-2026-62835
Exploitation
Related products
CVE list
- CVE-2026-35425 critical
- CVE-2026-49159 high
- CVE-2026-56160 critical
- CVE-2026-56165 critical
- CVE-2026-56167 critical
- CVE-2026-56163 critical
- CVE-2026-57106 critical
- CVE-2026-58630 critical
- CVE-2026-62835 critical
KB list
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!