T

Threats

Microsoft Discloses Three Critical Azure Vulnerabilities

Microsoft has published three critical security advisories affecting Azure services. Two vulnerabilities may allow an unauthorised remote attacker to elevate privileges. A third may allow an unauthorised attacker to disclose information through Azure Portal.

The vulnerabilities are:

  • CVE-2026-56163 affecting Azure Kubernetes Service, CVSS 10.0

  • CVE-2026-58630 affecting Azure App Service for Linux, CVSS 10.0

  • CVE-2026-62835 affecting Azure Portal, CVSS 9.3

All three records describe network-reachable issues requiring no existing privileges or user interaction. Organisations using these Azure services should confirm their exposure and follow Microsoft's latest guidance.


Affected Versions

Microsoft Azure Kubernetes Service – CVE-2026-56163

  • Affected: The vendor has not specified an exact affected-version range as of 24 July 2026.

  • Fixed: Microsoft has not published a customer-installable fixed version. The CVE is recorded as an exclusively hosted service issue. Reporting that cites Microsoft states the service-side issue has been fully mitigated and requires no customer action.

  • Not affected: Microsoft has not published unaffected versions or configurations.

  • Source: Microsoft Security Update Guide – CVE-2026-56163

Microsoft Azure App Service for Linux – CVE-2026-58630

  • Affected: The vendor has not specified an exact affected-version range as of 24 July 2026. Microsoft's CVE record identifies Azure App Service for Linux and uses an unspecified affected version.

  • Fixed: Microsoft has not published an exact fixed version or build in the sources available for review.

  • Not affected: Microsoft has not published unaffected versions or configurations.

  • Source: Microsoft Security Update Guide – CVE-2026-58630

Microsoft Azure Portal – CVE-2026-62835

  • Affected: The vendor has not specified an exact affected-version range as of 24 July 2026.

  • Fixed: Microsoft has not published a customer-installable fixed version or service remediation date in the sources available for review. The CVE is recorded as an exclusively hosted service issue.

  • Not affected: Microsoft has not published unaffected versions or configurations.

  • Source: Microsoft Security Update Guide – CVE-2026-62835


Vulnerability Breakdown

CVE-2026-56163 – Missing Authentication in Azure Kubernetes Service

  • Severity: Critical

  • CVSS: 10.0

  • Description: Missing authentication for a critical function in Azure Kubernetes Service may allow an unauthorised attacker to elevate privileges over a network.

  • Impact: Successful exploitation could result in high confidentiality, integrity and availability impact across a changed security scope.

  • Conditions: Network access is required. No privileges or user interaction are required.

  • Status: The record is classified as an exclusively hosted service issue. Microsoft has not published a customer-installable fixed version.

CVE-2026-58630 – Improper Access Control in Azure App Service for Linux

  • Severity: Critical

  • CVSS: 10.0

  • Description: Improper access control in Azure App Service may allow an unauthorised attacker to elevate privileges over a network.

  • Impact: Successful exploitation could result in high confidentiality and integrity impact across a changed security scope.

  • Conditions: Network access is required. No privileges or user interaction are required.

  • Status: Microsoft identifies Azure App Service for Linux as affected but has not published an exact affected or fixed version in the sources available for review.

CVE-2026-62835 – Improper Authorisation in Azure Portal

  • Severity: Critical

  • CVSS: 9.3

  • Description: Improper authorisation in Azure Portal may allow an unauthorised attacker to disclose information over a network.

  • Impact: Successful exploitation could expose information accessible through the affected Azure Portal function.

  • Conditions: Network access is required. No privileges or user interaction are required.

  • Status: The record is classified as an exclusively hosted service issue. Microsoft has not published a customer-installable fixed version.


Mitigation

  • Review the three Microsoft Security Update Guide entries and monitor them for updated service status, affected-version and remediation information.

  • For CVE-2026-56163, record Microsoft's reported provider-side mitigation and confirm there is no customer action for your tenancy.

  • For CVE-2026-58630, identify Azure App Service for Linux deployments and follow the Microsoft advisory for any service-specific update or operator action.

  • For CVE-2026-62835, monitor Microsoft guidance and Azure service communications for confirmation of provider-side remediation.

  • Continue to enforce least privilege, strong authentication and logging across Azure administrative identities and workloads.


Summary for IT Teams

  • Products: Microsoft Azure Kubernetes Service, Azure App Service for Linux and Azure Portal

  • Threat Level: Critical, CVSS 9.3 to 10.0

  • Action Required: Confirm whether the affected services are in use, review each Microsoft advisory, document the hosted-service status and apply any Microsoft-prescribed action as soon as it is published.


Reference


Need Help?

Secure ISS can help your organisation assess Azure exposure, validate controls and prioritise remediation. Call 1300 769 460 or contact the Secure ISS team.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.