T
Threats
Microsoft Discloses Three Critical Azure Vulnerabilities
Microsoft has published three critical security advisories affecting Azure services. Two vulnerabilities may allow an unauthorised remote attacker to elevate privileges. A third may allow an unauthorised attacker to disclose information through Azure Portal.
The vulnerabilities are:
CVE-2026-56163 affecting Azure Kubernetes Service, CVSS 10.0
CVE-2026-58630 affecting Azure App Service for Linux, CVSS 10.0
CVE-2026-62835 affecting Azure Portal, CVSS 9.3
All three records describe network-reachable issues requiring no existing privileges or user interaction. Organisations using these Azure services should confirm their exposure and follow Microsoft's latest guidance.
Affected Versions
Microsoft Azure Kubernetes Service – CVE-2026-56163
Affected: The vendor has not specified an exact affected-version range as of 24 July 2026.
Fixed: Microsoft has not published a customer-installable fixed version. The CVE is recorded as an exclusively hosted service issue. Reporting that cites Microsoft states the service-side issue has been fully mitigated and requires no customer action.
Not affected: Microsoft has not published unaffected versions or configurations.
Microsoft Azure App Service for Linux – CVE-2026-58630
Affected: The vendor has not specified an exact affected-version range as of 24 July 2026. Microsoft's CVE record identifies Azure App Service for Linux and uses an unspecified affected version.
Fixed: Microsoft has not published an exact fixed version or build in the sources available for review.
Not affected: Microsoft has not published unaffected versions or configurations.
Microsoft Azure Portal – CVE-2026-62835
Affected: The vendor has not specified an exact affected-version range as of 24 July 2026.
Fixed: Microsoft has not published a customer-installable fixed version or service remediation date in the sources available for review. The CVE is recorded as an exclusively hosted service issue.
Not affected: Microsoft has not published unaffected versions or configurations.
Vulnerability Breakdown
CVE-2026-56163 – Missing Authentication in Azure Kubernetes Service
Severity: Critical
CVSS: 10.0
Description: Missing authentication for a critical function in Azure Kubernetes Service may allow an unauthorised attacker to elevate privileges over a network.
Impact: Successful exploitation could result in high confidentiality, integrity and availability impact across a changed security scope.
Conditions: Network access is required. No privileges or user interaction are required.
Status: The record is classified as an exclusively hosted service issue. Microsoft has not published a customer-installable fixed version.
CVE-2026-58630 – Improper Access Control in Azure App Service for Linux
Severity: Critical
CVSS: 10.0
Description: Improper access control in Azure App Service may allow an unauthorised attacker to elevate privileges over a network.
Impact: Successful exploitation could result in high confidentiality and integrity impact across a changed security scope.
Conditions: Network access is required. No privileges or user interaction are required.
Status: Microsoft identifies Azure App Service for Linux as affected but has not published an exact affected or fixed version in the sources available for review.
CVE-2026-62835 – Improper Authorisation in Azure Portal
Severity: Critical
CVSS: 9.3
Description: Improper authorisation in Azure Portal may allow an unauthorised attacker to disclose information over a network.
Impact: Successful exploitation could expose information accessible through the affected Azure Portal function.
Conditions: Network access is required. No privileges or user interaction are required.
Status: The record is classified as an exclusively hosted service issue. Microsoft has not published a customer-installable fixed version.
Mitigation
Review the three Microsoft Security Update Guide entries and monitor them for updated service status, affected-version and remediation information.
For CVE-2026-56163, record Microsoft's reported provider-side mitigation and confirm there is no customer action for your tenancy.
For CVE-2026-58630, identify Azure App Service for Linux deployments and follow the Microsoft advisory for any service-specific update or operator action.
For CVE-2026-62835, monitor Microsoft guidance and Azure service communications for confirmation of provider-side remediation.
Continue to enforce least privilege, strong authentication and logging across Azure administrative identities and workloads.
Summary for IT Teams
Products: Microsoft Azure Kubernetes Service, Azure App Service for Linux and Azure Portal
Threat Level: Critical, CVSS 9.3 to 10.0
Action Required: Confirm whether the affected services are in use, review each Microsoft advisory, document the hosted-service status and apply any Microsoft-prescribed action as soon as it is published.
Reference
Need Help?
Secure ISS can help your organisation assess Azure exposure, validate controls and prioritise remediation. Call 1300 769 460 or contact the Secure ISS team.

