CVE-2026-23651Disclosure(microsoft / aci_confidential_containers)

LOWCVSS 6.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft aci_confidential_containers systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-625

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aci_confidential_containers

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked 4d ago at 2 mentions (2026-03-06); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
aci_confidential_containers

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-03-06: 2Mentions · 2026-03-07: 2Mentions · 2026-03-09: 1Mentions · 2026-03-26: 1Mentions · 2026-03-27: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-06: 2Technical Details · 2026-03-07: 2Technical Details · 2026-03-09: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-27: 103-0603-0703-0903-2603-27
Signal classification2 categories
Disclosure
571.4%
Patch
228.6%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-062
Disclosure2
2026-03-072
Disclosure1Patch1
2026-03-091
Disclosure1
2026-03-261
Disclosure1
2026-03-271
Patch1
Full discourse7 posts
  • White Rabbitx@TheRabbitPy
    Disclosure

    🛡️ MS ACI Containers crits: CVE-2026-23651/26124 (6.7 EoP). No wild exploits yet, but enterprise cloud alert! https://www.tenable.com/blog/microsofts-march-2026-patch-tuesday-addresses-83-cves-cve-2026-21262-cve-2026-26127

    Post summary

    The post highlights two newly disclosed CVEs in MS ACI Containers (CVE-2026-23651/26124), notes a 6.7 severity score, and indicates no active exploitation or PoC has yet been reported.

    0003074
    438 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #microsoft #定例外 2026. 3. 7 Microsoft ACI 上の機密コンテナーの特権昇格の脆弱性 CVE-2026-23651 Security Vulnerability リリース日: Mar 6, 2026 最終更新日: Mar 7, 2026 - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-23651

    Post summary

    Microsoft announced a patch for a privilege‑escalation flaw in ACI confidential containers (CVE‑2026‑23651) with no associated PoC, exploit code, or evidence of active exploitation.

    10100108
    89 followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    ☁️ Azure ACI Confidential Containers EoP (CVE-2026-23651 + CVE-2026-26124) Double priv-esc chain (CVSS 6.7 each) in confidential containers. Azure ACI users: Patch now. https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-march-2026/ #Azure #CVE

    Post summary

    Azure ACI Confidential Containers are affected by two 6.7 CVSS, double privilege‑escalation CVEs (CVE-2026-23651 and CVE-2026-26124) – users should apply the available patch immediately.

    0001075
    492 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 CVE-2026-23651 Security Vulnerability 影響: 特権の昇格 最大深刻度: 緊急 CVSS:3.1 6.7 / 6.0 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 悪用される可能性は低い https://x.com/kawn2020/status/2030111253511950777

    Post summary

    The post announces CVE‑2026‑23651 as a privilege‑escalation flaw with emergency severity, but reports no current exploitation, PoC, or patch, and does not challenge its validity.

    1000058
    89 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    ⚡ CVE-2026-23651: Microsoft ACI Confidential Conta... Regex bypass in Azure Compute Gallery breaks container isolation - high-priv attackers can escape confidential compute ... https://zerodaysignal.com/vulnerability/CVE-2026-23651 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A brief announcement of CVE‑2026‑23651 highlights a regex bypass enabling container isolation escape in Azure Compute Gallery, with no PoC, exploit code, patch, or active exploitation details provided.

    0000074
    140 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-23651 Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-23651 ----- Traducción: CVE-2026-23651 Expresión regular permisiva en Azure Compute Gallery per… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-23651, describing it as a permissive regular expression in Azure Compute Gallery that can lead to local privilege escalation, and provides a link to the CVE record.

    0000031
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23651 Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-23651

    Post summary

    The statement announces CVE-2026-23651 as a local privilege escalation vulnerability in Azure Compute Gallery, providing basic technical details but no PoC, exploit, patch, or evidence of active exploitation.

    00000184
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftaci_confidential_containers---

Explore more