Linuxsecurity SUSE and openSUSE Azure Storage AzCopy Security Update Addresses Critical Vulnerabilities
Article Content
- •Two critical vulnerabilities (CVE-2026-39821, CVE-2026-56852) fixed in the update.
- •CVE-2026-39821 allows privilege escalation through validation bypass.
- •Immediate patching is recommended for all users of azure-storage-azcopy.
An important security update for azure-storage-azcopy has been released, addressing two critical vulnerabilities: CVE-2026-39821 and CVE-2026-56852. CVE-2026-39821 allows for validation bypass and privilege escalation due to improper handling of Punycode-encoded labels, while CVE-2026-56852 can lead to an infinite loop from invalid UTF-8 input. Both vulnerabilities affect systems using the azcopy tool, with potential impacts on data integrity and system security. The update includes version 10.32.6, which also implements compliance with the FIPS 140-3 standard. Users are advised to apply the patches immediately to mitigate risks. The vulnerabilities were published on May 22 and July 21, 2026, respectively. The update is critical for maintaining the security of affected systems.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track SuSE and CVE-2026-39821 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Multiple Oracle Linux Security Updates Address Critical Vulnerabilities Oracle has released multiple security updates for its Linux distributions, addressing several critical vulnerabilities. Key updates include patches for CVE-2026-59090 and CVE-2026-18301 in GIMP, and multiple CVEs in FreeRDP, libssh, and Grafana. Affected systems include Oracle Linux 8, 9, and 10, with vulnerabilities…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…