T
Threats
Microsoft Multiple Critical Vulnerabilities
Overview
CVE: CVE-2026-50516, CVE-2026-59124, CVE-2026-62815, CVE-2026-62878, CVE-2026-62893, CVE-2026-65791, CVE-2026-70306
Severity: Critical
Date: 11 August 2026
Highest CVSS: 9.8
Affected Versions
Azure Kubernetes Service - CVE-2026-50516
Affected: The vendor has not specified an exact affected-version range as of 11 August 2026.
Fixed: Microsoft identifies this as an exclusively hosted service issue and states that no customer action is required.
Not affected: No unaffected versions or configurations have been stated.
Source: Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
HPC Pack and Windows App Client - CVE-2026-59124
Affected: Windows App Client for Windows Desktop versions from 1.00 to earlier than 2.0.1314.0. Microsoft's description identifies the vulnerable component as Microsoft High Performance Computing Pack.
Fixed: 2.0.1314.0 or later.
Not affected: Versions 2.0.1314.0 and later are outside the published affected range.
Source: Microsoft HPC Pack Remote Code Execution Vulnerability
Microsoft QUIC - CVE-2026-62815
Affected: Windows 11 23H2 builds 10.0.22631.0 to earlier than 10.0.22631.7517; Windows 11 24H2 builds 10.0.26100.0 to earlier than 10.0.26100.9168; Windows 11 25H2 builds 10.0.26200.0 to earlier than 10.0.26200.9168; Windows 11 26H1 builds 10.0.28000.0 to earlier than 10.0.28000.2704; Windows Server 2022 builds 10.0.20348.0 to earlier than 10.0.20348.5499; Windows Server 2025, including Server Core, builds 10.0.26100.0 to earlier than 10.0.26100.33296.
Fixed: Builds 10.0.22631.7517, 10.0.26100.9168, 10.0.26200.9168, 10.0.28000.2704, 10.0.20348.5499 and 10.0.26100.33296 respectively, or later.
Not affected: Builds at or above the applicable fixed build are outside the published affected ranges.
Windows DNS Server - CVE-2026-62878
Affected: Windows 10 1607 before build 10.0.14393.9418; Windows 10 1809 before 10.0.17763.9115; Windows Server 2012 before 6.2.9200.26280; Windows Server 2012 R2 before 6.3.9600.23338; Windows Server 2016 before 10.0.14393.9418; Windows Server 2019 before 10.0.17763.9115; Windows Server 2022 before 10.0.20348.5499; Windows Server 2025 before 10.0.26100.33296. Server Core installations are included where Microsoft lists them.
Fixed: The corresponding builds listed above, or later.
Not affected: Builds at or above the applicable fixed build are outside the published affected ranges.
Source: Windows DNS Server Remote Code Execution Vulnerability
Windows Deployment Services - CVE-2026-62893
Affected: Windows 10 1607 before build 10.0.14393.9418; Windows 10 1809 before 10.0.17763.9115; Windows Server 2012 before 6.2.9200.26280; Windows Server 2012 R2 before 6.3.9600.23338; Windows Server 2016 before 10.0.14393.9418; Windows Server 2019 before 10.0.17763.9115; Windows Server 2022 before 10.0.20348.5499; Windows Server 2025 before 10.0.26100.33296. Server Core installations are included where Microsoft lists them.
Fixed: The corresponding builds listed above, or later.
Not affected: Builds at or above the applicable fixed build are outside the published affected ranges.
Source: Windows Deployment Services TFTP Server Remote Code Execution Vulnerability
Windows iSCSI Target Service - CVE-2026-65791
Affected: Windows 10 1607 before build 10.0.14393.9418; Windows 10 1809 before 10.0.17763.9115; Windows Server 2012 before 6.2.9200.26280; Windows Server 2012 R2 before 6.3.9600.23338; Windows Server 2016 before 10.0.14393.9418; Windows Server 2019 before 10.0.17763.9115; Windows Server 2022 before 10.0.20348.5499; Windows Server 2025 before 10.0.26100.33296. Server Core installations are included where Microsoft lists them.
Fixed: The corresponding builds listed above, or later.
Not affected: Builds at or above the applicable fixed build are outside the published affected ranges.
Source: Windows iSCSI Target Service Remote Code Execution Vulnerability
Microsoft SharePoint Server - CVE-2026-70306
Affected: SharePoint Enterprise Server 2016 builds 16.0.0 to earlier than 16.0.5561.1001; SharePoint Server 2019 builds 16.0.0 to earlier than 16.0.10417.20175; SharePoint Server Subscription Edition builds 16.0.0 to earlier than 16.0.19725.20434.
Fixed: 16.0.5561.1001, 16.0.10417.20175 and 16.0.19725.20434 respectively, or later.
Not affected: Builds at or above the applicable fixed build are outside the published affected ranges.
Vulnerability Breakdown
CVE-2026-59124 - Deserialization of Untrusted Data
Severity: Critical
CVSS: 9.8
Description: Deserialization of untrusted data in Microsoft HPC Pack can allow an unauthorised attacker to execute code over a network.
Impact: Remote code execution with high confidentiality, integrity and availability impact.
Conditions: Network access is required. No privileges or user interaction are required according to Microsoft's CVSS vector.
CVE-2026-62815 - Microsoft QUIC Use After Free
Severity: Critical
CVSS: 9.8
Description: A use-after-free flaw in Microsoft QUIC can allow an unauthorised attacker to execute code over a network.
Impact: Remote code execution and potential system compromise.
Conditions: Network access is required. No privileges or user interaction are required.
CVE-2026-62878 - Windows DNS Stack Buffer Overflow
Severity: Critical
CVSS: 9.8
Description: A stack-based buffer overflow in Windows DNS can allow an unauthorised attacker to execute code over a network.
Impact: Remote code execution on affected systems running the vulnerable Windows DNS component.
Conditions: Network access is required. No privileges or user interaction are required.
CVE-2026-62893 - Windows Deployment Services Use After Free
Severity: Critical
CVSS: 9.8
Description: A use-after-free flaw in the Windows Deployment Services TFTP Server can allow an unauthorised attacker to execute code over a network.
Impact: Remote code execution on affected systems where the vulnerable component is present.
Conditions: Network access is required. No privileges or user interaction are required.
CVE-2026-65791 - Windows iSCSI Target Service Heap Buffer Overflow
Severity: Critical
CVSS: 9.8
Description: A heap-based buffer overflow in Windows iSCSI Target Service can allow an unauthorised attacker to execute code over a network.
Impact: Remote code execution and potential compromise of affected servers.
Conditions: Network access is required. No privileges or user interaction are required.
CVE-2026-50516 - Missing Authentication in Azure Kubernetes Service
Severity: Critical
CVSS: 9.4
Description: Missing authentication for a critical function in Azure Kubernetes Service can allow an unauthorised network attacker to elevate privileges.
Impact: Privilege elevation with high confidentiality and integrity impact.
Conditions: Network access is required. No privileges or user interaction are required. Microsoft states that no customer action is required.
CVE-2026-70306 - SharePoint Cross-Site Scripting
Severity: Critical
CVSS: 9.3
Description: Improper neutralisation of input during web page generation in Microsoft Office SharePoint can allow an unauthorised attacker to perform spoofing over a network.
Impact: Spoofed or malicious content may affect confidentiality and integrity within the user's security context.
Conditions: Network access and user interaction are required. No prior privileges are required according to Microsoft's CVSS vector.
Mitigation
Identify affected Azure, Windows, HPC Pack and SharePoint assets using the version and build ranges above.
Deploy the applicable Microsoft security updates that raise each installation to the fixed build or a later supported build.
Prioritise internet-facing DNS, SharePoint, Windows Deployment Services, iSCSI and QUIC-enabled systems.
For Azure Kubernetes Service, review the Microsoft advisory. Microsoft identifies this as an exclusively hosted service issue and states that no customer action is required.
Validate update deployment by confirming the installed build after patching.
Restrict unnecessary network exposure to affected services until updates are applied.
Summary for IT Teams
Products: Microsoft Azure Kubernetes Service, HPC Pack, Windows App Client, Microsoft QUIC, Windows DNS, Windows Deployment Services, Windows iSCSI Target Service and SharePoint Server
Threat Level: Critical, CVSS up to 9.8
Action Required: Assess exposure immediately, apply the applicable Microsoft updates and verify fixed builds. Review the Microsoft advisory for CVE-2026-50516, noting that no customer action is required.
Reference
Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
Windows Deployment Services TFTP Server Remote Code Execution Vulnerability
Windows iSCSI Target Service Remote Code Execution Vulnerability
Need Help?
Secure ISS can help your organisation assess exposure, prioritise remediation and verify that security updates have been deployed correctly. Contact us on 1300 769 460.

