Skip to content
Microsoft Discloses Three Critical Azure Vulnerabilities

Microsoft Discloses Three Critical Azure Vulnerabilities

Secure-Iss July 28, 2026

Microsoft has published three critical security advisories affecting Azure services. Two vulnerabilities may allow an unauthorised remote attacker to elevate privileges. A third may allow an unauthorised attacker to disclose information through Azure Portal.

The vulnerabilities are:

CVE-2026-56163 affecting Azure Kubernetes Service, CVSS 10.0

CVE-2026-58630 affecting Azure App Service for Linux, CVSS 10.0

CVE-2026-62835 affecting Azure Portal, CVSS 9.3

All three records describe network-reachable issues requiring no existing privileges or user interaction. Organisations using these Azure services should confirm their exposure and follow Microsoft's latest guidance.

Affected: The vendor has not specified an exact affected-version range as of 24 July 2026.

Fixed: Microsoft has not published a customer-installable fixed version. The CVE is recorded as an exclusively hosted service issue. Reporting that cites Microsoft states the service-side issue has been fully mitigated and requires no customer action.

Not affected: Microsoft has not published unaffected versions or configurations.

Source: Microsoft Security Update Guide – CVE-2026-56163

Affected: The vendor has not specified an exact affected-version range as of 24 July 2026. Microsoft's CVE record identifies Azure App Service for Linux and uses an unspecified affected version.

Fixed: Microsoft has not published an exact fixed version or build in the sources available for review.

Not affected: Microsoft has not published unaffected versions or configurations.

Source: Microsoft Security Update Guide – CVE-2026-58630

Affected: The vendor has not specified an exact affected-version range as of 24 July 2026.

Fixed: Microsoft has not published a customer-installable fixed version or service remediation date in the sources available for review. The CVE is recorded as an exclusively hosted service issue.

Not affected: Microsoft has not published unaffected versions or configurations.

Source: Microsoft Security Update Guide – CVE-2026-62835

Description: Missing authentication for a critical function in Azure Kubernetes Service may allow an unauthorised attacker to elevate privileges over a network.

Impact: Successful exploitation could result in high confidentiality, integrity and availability impact across a changed security scope.

Conditions: Network access is required. No privileges or user interaction are required.

Status: The record is classified as an exclusively hosted service issue. Microsoft has not published a customer-installable fixed version.

Description: Improper access control in Azure App Service may allow an unauthorised attacker to elevate privileges over a network.

Impact: Successful exploitation could result in high confidentiality and integrity impact across a changed security scope.

Conditions: Network access is required. No privileges or user interaction are required.

Status: Microsoft identifies Azure App Service for Linux as affected but has not published an exact affected or fixed version in the sources available for review.

Description: Improper authorisation in Azure Portal may allow an unauthorised attacker to disclose information over a network.

Impact: Successful exploitation could expose information accessible through the affected Azure Portal function.

Conditions: Network access is required. No privileges or user interaction are required.

Status: The record is classified as an exclusively hosted service issue. Microsoft has not published a customer-installable fixed version.

Review the three Microsoft Security Update Guide entries and monitor them for updated service status, affected-version and remediation information.

For CVE-2026-56163, record Microsoft's reported provider-side mitigation and confirm there is no customer action for your tenancy.

For CVE-2026-58630, identify Azure App Service for Linux deployments and follow the Microsoft advisory for any service-specific update or operator action.

For CVE-2026-62835, monitor Microsoft guidance and Azure service communications for confirmation of provider-side remediation.

Continue to enforce least privilege, strong authentication and logging across Azure administrative identities and workloads.

Products: Microsoft Azure Kubernetes Service, Azure App Service for Linux and Azure Portal

Threat Level: Critical, CVSS 9.3 to 10.0

Action Required: Confirm whether the affected services are in use, review each Microsoft advisory, document the hosted-service status and apply any Microsoft-prescribed action as soon as it is published.

Microsoft Security Update Guide – CVE-2026-56163

Microsoft Security Update Guide – CVE-2026-58630

Microsoft Security Update Guide – CVE-2026-62835

NVD Record – CVE-2026-56163

NVD Record – CVE-2026-58630

NVD Record – CVE-2026-62835

Secure ISS can help your organisation assess Azure exposure, validate controls and prioritise remediation. Call 1300 769 460 or the Secure ISS team.

Reach out today to how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Reach out today to how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Reach out today to how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.