Skip to content
ThreatCluster

Multiple Elevation of Privilege Vulnerabilities in Azure Arc and Linux VMs

First seen 10 Mar 2026, 17:28 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

Three critical elevation of privilege vulnerabilities have been identified in Azure services, affecting both Windows and Linux virtual machines. CVE-2026-26141 and CVE-2026-26117 involve improper authentication and authentication bypass in Azure Arc-enabled Windows VMs, while CVE-2026-23665 pertains to a heap-based buffer overflow in Azure Linux VMs, all allowing authorized attackers to elevate privileges locally.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 210d ago How this analysis works

Timeline

2026-03-10
CVE-2026-26117 published
2026-03-10
CVE-2026-26141 published
2026-03-10
CVE-2026-23665 published

More articles in this cluster (3)

Following this threat?

Track Azure and CVE-2026-23665 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed