Petri Microsoft Addresses Critical Azure Automation Vulnerability CVE-2025-29827
Article Content
- •CVE-2025-29827 is a critical privilege escalation vulnerability in Azure Automation.
- •Attackers could exploit the flaw to access resources across Azure tenants with low-level privileges.
- •Microsoft has released security updates and changed default configurations to mitigate the risk.
Microsoft has fixed a critical vulnerability in Azure Automation, tracked as CVE-2025-29827, which could allow authorized attackers to elevate privileges and access resources across Azure tenants. Discovered by Shay Shavit and reported in May 2025, the flaw has a CVSS score of 9.9 and stems from improper authorization in the service. Attackers could exploit this vulnerability remotely with low-level privileges, potentially impersonating other organizations' automation identities. Microsoft has updated the default configurations and recommends organizations to verify their Azure Automation accounts and permissions. The flaw could be combined with misconfigurations to cross trust boundaries between Azure tenants, posing a significant risk to sensitive cloud resources. Organizations are advised to apply the latest security updates and follow best practices to mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (14)
Following this threat?
Track Microsoft and CVE-2025-29827 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…