Description
Multiple vulnerabilities were found in Microsoft Azure. Malicious users can exploit these vulnerabilities to bypass security restrictions, execute arbitrary code, gain privileges, obtain sensitive information, spoof user interface.
Below is a complete list of vulnerabilities:
- An elevation of privilege vulnerability in Azure Monitor Agent can be exploited remotely to gain privileges.
- A remote code execution vulnerability in Microsoft High Performance Computing (HPC) Pack can be exploited remotely to execute arbitrary code.
- An elevation of privilege vulnerability in Microsoft High Performance Computing (HPC) Pack can be exploited remotely to gain privileges.
- An elevation of privilege vulnerability in Microsoft Entra Connect can be exploited remotely to gain privileges.
- An information disclosure vulnerability in Azure CycleCloud can be exploited remotely to obtain sensitive information.
- Security UI vulnerability can be exploited to spoof user interface.
- An information disclosure vulnerability in Microsoft COM for Windows can be exploited remotely to obtain sensitive information.
- An elevation of privilege vulnerability in Azure CycleCloud can be exploited remotely to gain privileges.
Original advisories
- CVE-2026-65673
- CVE-2026-65806
- CVE-2026-6726
- CVE-2026-6727
- CVE-2026-70340
- CVE-2026-59124
- CVE-2026-59133
Exploitation
Related products
CVE list
- CVE-2026-6726 critical
- CVE-2026-6727 high
- CVE-2026-47299 high
- CVE-2026-59124 unknown
- CVE-2026-59133 unknown
- CVE-2026-65673 critical
- CVE-2026-65806 high
- CVE-2026-70340 critical
KB list
Read more
Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com
Found an inaccuracy in the description of this vulnerability? Let us know!