T

Threats

Microsoft Multiple Critical Vulnerabilities

Overview


Affected Versions

Azure Kubernetes Service - CVE-2026-50516

  • Affected: The vendor has not specified an exact affected-version range as of 11 August 2026.

  • Fixed: Microsoft identifies this as an exclusively hosted service issue and states that no customer action is required.

  • Not affected: No unaffected versions or configurations have been stated.

  • Source: Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

HPC Pack and Windows App Client - CVE-2026-59124

  • Affected: Windows App Client for Windows Desktop versions from 1.00 to earlier than 2.0.1314.0. Microsoft's description identifies the vulnerable component as Microsoft High Performance Computing Pack.

  • Fixed: 2.0.1314.0 or later.

  • Not affected: Versions 2.0.1314.0 and later are outside the published affected range.

  • Source: Microsoft HPC Pack Remote Code Execution Vulnerability

Microsoft QUIC - CVE-2026-62815

  • Affected: Windows 11 23H2 builds 10.0.22631.0 to earlier than 10.0.22631.7517; Windows 11 24H2 builds 10.0.26100.0 to earlier than 10.0.26100.9168; Windows 11 25H2 builds 10.0.26200.0 to earlier than 10.0.26200.9168; Windows 11 26H1 builds 10.0.28000.0 to earlier than 10.0.28000.2704; Windows Server 2022 builds 10.0.20348.0 to earlier than 10.0.20348.5499; Windows Server 2025, including Server Core, builds 10.0.26100.0 to earlier than 10.0.26100.33296.

  • Fixed: Builds 10.0.22631.7517, 10.0.26100.9168, 10.0.26200.9168, 10.0.28000.2704, 10.0.20348.5499 and 10.0.26100.33296 respectively, or later.

  • Not affected: Builds at or above the applicable fixed build are outside the published affected ranges.

  • Source: Microsoft QUIC Remote Code Execution Vulnerability

Windows DNS Server - CVE-2026-62878

  • Affected: Windows 10 1607 before build 10.0.14393.9418; Windows 10 1809 before 10.0.17763.9115; Windows Server 2012 before 6.2.9200.26280; Windows Server 2012 R2 before 6.3.9600.23338; Windows Server 2016 before 10.0.14393.9418; Windows Server 2019 before 10.0.17763.9115; Windows Server 2022 before 10.0.20348.5499; Windows Server 2025 before 10.0.26100.33296. Server Core installations are included where Microsoft lists them.

  • Fixed: The corresponding builds listed above, or later.

  • Not affected: Builds at or above the applicable fixed build are outside the published affected ranges.

  • Source: Windows DNS Server Remote Code Execution Vulnerability

Windows Deployment Services - CVE-2026-62893

  • Affected: Windows 10 1607 before build 10.0.14393.9418; Windows 10 1809 before 10.0.17763.9115; Windows Server 2012 before 6.2.9200.26280; Windows Server 2012 R2 before 6.3.9600.23338; Windows Server 2016 before 10.0.14393.9418; Windows Server 2019 before 10.0.17763.9115; Windows Server 2022 before 10.0.20348.5499; Windows Server 2025 before 10.0.26100.33296. Server Core installations are included where Microsoft lists them.

  • Fixed: The corresponding builds listed above, or later.

  • Not affected: Builds at or above the applicable fixed build are outside the published affected ranges.

  • Source: Windows Deployment Services TFTP Server Remote Code Execution Vulnerability

Windows iSCSI Target Service - CVE-2026-65791

  • Affected: Windows 10 1607 before build 10.0.14393.9418; Windows 10 1809 before 10.0.17763.9115; Windows Server 2012 before 6.2.9200.26280; Windows Server 2012 R2 before 6.3.9600.23338; Windows Server 2016 before 10.0.14393.9418; Windows Server 2019 before 10.0.17763.9115; Windows Server 2022 before 10.0.20348.5499; Windows Server 2025 before 10.0.26100.33296. Server Core installations are included where Microsoft lists them.

  • Fixed: The corresponding builds listed above, or later.

  • Not affected: Builds at or above the applicable fixed build are outside the published affected ranges.

  • Source: Windows iSCSI Target Service Remote Code Execution Vulnerability

Microsoft SharePoint Server - CVE-2026-70306

  • Affected: SharePoint Enterprise Server 2016 builds 16.0.0 to earlier than 16.0.5561.1001; SharePoint Server 2019 builds 16.0.0 to earlier than 16.0.10417.20175; SharePoint Server Subscription Edition builds 16.0.0 to earlier than 16.0.19725.20434.

  • Fixed: 16.0.5561.1001, 16.0.10417.20175 and 16.0.19725.20434 respectively, or later.

  • Not affected: Builds at or above the applicable fixed build are outside the published affected ranges.

  • Source: Microsoft Office SharePoint Spoofing Vulnerability


Vulnerability Breakdown

CVE-2026-59124 - Deserialization of Untrusted Data

  • Severity: Critical

  • CVSS: 9.8

  • Description: Deserialization of untrusted data in Microsoft HPC Pack can allow an unauthorised attacker to execute code over a network.

  • Impact: Remote code execution with high confidentiality, integrity and availability impact.

  • Conditions: Network access is required. No privileges or user interaction are required according to Microsoft's CVSS vector.

CVE-2026-62815 - Microsoft QUIC Use After Free

  • Severity: Critical

  • CVSS: 9.8

  • Description: A use-after-free flaw in Microsoft QUIC can allow an unauthorised attacker to execute code over a network.

  • Impact: Remote code execution and potential system compromise.

  • Conditions: Network access is required. No privileges or user interaction are required.

CVE-2026-62878 - Windows DNS Stack Buffer Overflow

  • Severity: Critical

  • CVSS: 9.8

  • Description: A stack-based buffer overflow in Windows DNS can allow an unauthorised attacker to execute code over a network.

  • Impact: Remote code execution on affected systems running the vulnerable Windows DNS component.

  • Conditions: Network access is required. No privileges or user interaction are required.

CVE-2026-62893 - Windows Deployment Services Use After Free

  • Severity: Critical

  • CVSS: 9.8

  • Description: A use-after-free flaw in the Windows Deployment Services TFTP Server can allow an unauthorised attacker to execute code over a network.

  • Impact: Remote code execution on affected systems where the vulnerable component is present.

  • Conditions: Network access is required. No privileges or user interaction are required.

CVE-2026-65791 - Windows iSCSI Target Service Heap Buffer Overflow

  • Severity: Critical

  • CVSS: 9.8

  • Description: A heap-based buffer overflow in Windows iSCSI Target Service can allow an unauthorised attacker to execute code over a network.

  • Impact: Remote code execution and potential compromise of affected servers.

  • Conditions: Network access is required. No privileges or user interaction are required.

CVE-2026-50516 - Missing Authentication in Azure Kubernetes Service

  • Severity: Critical

  • CVSS: 9.4

  • Description: Missing authentication for a critical function in Azure Kubernetes Service can allow an unauthorised network attacker to elevate privileges.

  • Impact: Privilege elevation with high confidentiality and integrity impact.

  • Conditions: Network access is required. No privileges or user interaction are required. Microsoft states that no customer action is required.

CVE-2026-70306 - SharePoint Cross-Site Scripting

  • Severity: Critical

  • CVSS: 9.3

  • Description: Improper neutralisation of input during web page generation in Microsoft Office SharePoint can allow an unauthorised attacker to perform spoofing over a network.

  • Impact: Spoofed or malicious content may affect confidentiality and integrity within the user's security context.

  • Conditions: Network access and user interaction are required. No prior privileges are required according to Microsoft's CVSS vector.


Mitigation

  • Identify affected Azure, Windows, HPC Pack and SharePoint assets using the version and build ranges above.

  • Deploy the applicable Microsoft security updates that raise each installation to the fixed build or a later supported build.

  • Prioritise internet-facing DNS, SharePoint, Windows Deployment Services, iSCSI and QUIC-enabled systems.

  • For Azure Kubernetes Service, review the Microsoft advisory. Microsoft identifies this as an exclusively hosted service issue and states that no customer action is required.

  • Validate update deployment by confirming the installed build after patching.

  • Restrict unnecessary network exposure to affected services until updates are applied.


Summary for IT Teams

  • Products: Microsoft Azure Kubernetes Service, HPC Pack, Windows App Client, Microsoft QUIC, Windows DNS, Windows Deployment Services, Windows iSCSI Target Service and SharePoint Server

  • Threat Level: Critical, CVSS up to 9.8

  • Action Required: Assess exposure immediately, apply the applicable Microsoft updates and verify fixed builds. Review the Microsoft advisory for CVE-2026-50516, noting that no customer action is required.


Reference


Need Help?

Secure ISS can help your organisation assess exposure, prioritise remediation and verify that security updates have been deployed correctly. Contact us on 1300 769 460.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.