Microsoft has published three critical security advisories affecting Azure services. Two vulnerabilities may allow an unauthorised remote attacker to elevate privileges. A third may allow an unauthorised attacker to disclose information through Azure Portal.
The vulnerabilities are:
CVE-2026-56163 affecting Azure Kubernetes Service, CVSS 10.0
CVE-2026-58630 affecting Azure App Service for Linux, CVSS 10.0
CVE-2026-62835 affecting Azure Portal, CVSS 9.3
All three records describe network-reachable issues requiring no existing privileges or user interaction. Organisations using these Azure services should confirm their exposure and follow Microsoft's latest guidance.
Affected: The vendor has not specified an exact affected-version range as of 24 July 2026.
Fixed: Microsoft has not published a customer-installable fixed version. The CVE is recorded as an exclusively hosted service issue. Reporting that cites Microsoft states the service-side issue has been fully mitigated and requires no customer action.
Not affected: Microsoft has not published unaffected versions or configurations.
Source: Microsoft Security Update Guide – CVE-2026-56163
Affected: The vendor has not specified an exact affected-version range as of 24 July 2026. Microsoft's CVE record identifies Azure App Service for Linux and uses an unspecified affected version.
Fixed: Microsoft has not published an exact fixed version or build in the sources available for review.
Not affected: Microsoft has not published unaffected versions or configurations.
Source: Microsoft Security Update Guide – CVE-2026-58630
Affected: The vendor has not specified an exact affected-version range as of 24 July 2026.
Fixed: Microsoft has not published a customer-installable fixed version or service remediation date in the sources available for review. The CVE is recorded as an exclusively hosted service issue.
Not affected: Microsoft has not published unaffected versions or configurations.
Source: Microsoft Security Update Guide – CVE-2026-62835
Description: Missing authentication for a critical function in Azure Kubernetes Service may allow an unauthorised attacker to elevate privileges over a network.
Impact: Successful exploitation could result in high confidentiality, integrity and availability impact across a changed security scope.
Conditions: Network access is required. No privileges or user interaction are required.
Status: The record is classified as an exclusively hosted service issue. Microsoft has not published a customer-installable fixed version.
Description: Improper access control in Azure App Service may allow an unauthorised attacker to elevate privileges over a network.
Impact: Successful exploitation could result in high confidentiality and integrity impact across a changed security scope.
Conditions: Network access is required. No privileges or user interaction are required.
Status: Microsoft identifies Azure App Service for Linux as affected but has not published an exact affected or fixed version in the sources available for review.
Description: Improper authorisation in Azure Portal may allow an unauthorised attacker to disclose information over a network.
Impact: Successful exploitation could expose information accessible through the affected Azure Portal function.
Conditions: Network access is required. No privileges or user interaction are required.
Status: The record is classified as an exclusively hosted service issue. Microsoft has not published a customer-installable fixed version.
Review the three Microsoft Security Update Guide entries and monitor them for updated service status, affected-version and remediation information.
For CVE-2026-56163, record Microsoft's reported provider-side mitigation and confirm there is no customer action for your tenancy.
For CVE-2026-58630, identify Azure App Service for Linux deployments and follow the Microsoft advisory for any service-specific update or operator action.
For CVE-2026-62835, monitor Microsoft guidance and Azure service communications for confirmation of provider-side remediation.
Continue to enforce least privilege, strong authentication and logging across Azure administrative identities and workloads.
Products: Microsoft Azure Kubernetes Service, Azure App Service for Linux and Azure Portal
Threat Level: Critical, CVSS 9.3 to 10.0
Action Required: Confirm whether the affected services are in use, review each Microsoft advisory, document the hosted-service status and apply any Microsoft-prescribed action as soon as it is published.
Microsoft Security Update Guide – CVE-2026-56163
Microsoft Security Update Guide – CVE-2026-58630
Microsoft Security Update Guide – CVE-2026-62835
NVD Record – CVE-2026-56163
NVD Record – CVE-2026-58630
NVD Record – CVE-2026-62835
Secure ISS can help your organisation assess Azure exposure, validate controls and prioritise remediation. Call 1300 769 460 or the Secure ISS team.
Reach out today to how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.
Reach out today to how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.
Reach out today to how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
