CVE-2026-24300Disclosure(microsoft / azure_front_door)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch microsoft azure_front_door systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Azure Front Door Elevation of Privilege Vulnerability

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_front_door

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 12 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 8 classified signals
  • General: 3 classified signals
  • Peaked 3d ago at 5 mentions (2026-02-06); latest day: 1
  • 12 total mentions across 5 days

Affected systems

Vendors
Products
azure_front_door

1 version affected across 1 product

Deep dive

Activity timeline12 mentions / 5d
01345Mentions · 2026-02-05: 2Mentions · 2026-02-06: 5Mentions · 2026-02-11: 3Mentions · 2026-02-12: 1Mentions · 2026-02-26: 1Active Exploitation · 2026-02-11: 1Patch / Workaround · 2026-02-11: 1Patch / Workaround · 2026-02-26: 1Technical Details · 2026-02-06: 3Technical Details · 2026-02-11: 1Technical Details · 2026-02-26: 102-0502-0602-1102-1202-26
Signal classification3 categories
Disclosure
866.7%
General
325.0%
Active Exploitation
18.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-02-052
General2
2026-02-065
Disclosure5
2026-02-113
Active Exploitation1Disclosure1General1
2026-02-121
Disclosure1
2026-02-261
Disclosure1
Full discourse12 posts
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Microsoft ❗ CVE-2026-24300 ❗ CVE-2026-21510 ❗ CVE-2026-20841 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-microsoft-5/ https://t.co/hlwmGgx7eh

    Post summary

    The tweet announces three new Microsoft CVEs and directs readers to external links for more information, without providing technical details, PoCs, or exploitation evidence.

    10043274
    6.6K followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 2026. 2. 5 Azure Front Door の特権昇格の脆弱性 CVE-2026-24300 Security Vulnerability リリース日: Feb 5, 2026 - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24300

    Post summary

    Microsoft issued a security update for CVE‑2026‑24300, a privilege‑escalation flaw in Azure Front Door, and provided a link to the official MSRC advisory.

    10100157
    89 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-24300: CRITICAL] Azure Front Door Elevation of Privilege Vulnerability#cve,CVE-2026-24300,#cybersecurity https://cvefind.com/CVE-2026-24300

    Post summary

    The tweet announces a critical elevation‑of‑privilege vulnerability in Azure Front Door (CVE‑2026‑24300) but provides no PoC, exploit, or mitigation details.

    0101097
    583 followersView on X
  • kawn@kawn2020
    General

    #windowsupdate #microsoft -CVSS 基本値が 9.8 以上のもの:2 件 ・CVE-2026-21531 9.8 Azure SDK ・CVE-2026-24300 9.8 Azure Front Door (AFD)

    Post summary

    The tweet lists two high‑CVSS CVEs affecting Azure services without providing exploitation, patch, or detailed technical information.

    1000067
    89 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 CVE-2026-24300 Security Vulnerability 影響: 特権の昇格 最大深刻度: 緊急 CVSS:3.1 9.8 / 8.5 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 対象外 https://x.com/kawn2020/status/2019668810312348028

    Post summary

    The tweet announces CVE-2026-24300, a high‑severity privilege escalation vulnerability, but does not provide evidence of exploitation, PoC, or patches.

    1000061
    89 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-24300 Azure Front Door Elevation of Privilege Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-24300

    Post summary

    The text briefly references CVE‑2026‑24300, an elevation‑of‑privilege issue in Azure Front Door, but provides only the CVE link with no additional technical or operational details.

    00010224
    56.5K followersView on X
  • GainTech Consulting@johnboston35100
    Disclosure

    Microsoft’s Feb 2026 Patch Tuesday has dropped two massive CVSS 9.8 vulnerabilities. If you’re managing Azure environments, these need your immediate attention: CVE-2026-21531 (Azure SDK): Critical RCE risk CVE-2026-24300 (Azure Front Door): Major flaw in CDN & Security services https://t.co/LCzPvtWPzm

    Post summary

    Microsoft’s Feb 2026 Patch Tuesday introduced two high‑severity CVEs—CVE‑2026‑21531 (Azure SDK) with a critical RCE risk and CVE‑2026‑24300 (Azure Front Door) affecting CDN and security services—requiring immediate patching.

    0000046
  • Ostorlab@OstorlabSec
    Active Exploitation

    🚨 CVE-2026-24300: AZURE FRONT DOOR PRIVILEGE ESCALATION ALERT 🚨 A critical-severity privilege escalation vulnerability has been disclosed in Azure Front Door, enabling unauthenticated attackers to gain administrative control over CDN configurations. Active exploitation has been confirmed in multi-tenant environments. Risk Severity: Critical (Privilege Escalation, CVSS 9.8, confirmed active exploitation, cross-tenant risk) Impact:     Unauthorized access to global routing configurations     Exposure of managed SSL/TLS certificate private keys     Global CDN cache poisoning and malicious content injection     Cross-tenant metadata and PII leakage     Service disruption at enterprise scale Root Cause: CWE-269 (Improper Privilege Management) A logic flaw in the Azure Resource Manager (ARM) authorization layer fails to validate tenant boundaries during API calls, allowing attackers to elevate to "Contributor" roles. Attackers can:     Extract SSL certificate metadata via the secrets API     Inject malicious origin backends into routing rules     Retrieve cached authentication tokens and PII from global endpoints     Pivot to connected Azure Functions or App Services Are You Affected? Vulnerable:     All Azure Front Door Standard/Premium deployments prior to Feb 11, 2026 Fixed in:     Platform-level patch deployed by Microsoft (Feb 2026) Immediate Action Required: Update/Patch:     No customer patch required (Platform-fixed), but remediation of credentials is mandatory. Mitigation (if you cannot patch immediately):     Enable Private Link for all Front Door origins     Restrict http://management.azure.com access via Conditional Access policies     Deploy Azure Policy to block /secrets endpoint access Audit & Monitor:     Hunt for unauthorized listKeys operations in Azure Activity Logs     Monitor for non-standard origin backend additions in routing configurations     Alert on cross-tenant resource access patterns in AzureDiagnostics Given Azure Front Door’s position as your global entry point, this vulnerability represents a total loss of traffic integrity, patch immediately and hunt aggressively. 🌐  #ostorlabCVE

    Post summary

    Critical privilege escalation in Azure Front Door has confirmed active exploitation; Microsoft has deployed a platform patch and recommends immediate mitigation measures.

    00000109
    581 followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-24300 | Azure Front Door Elevation of Privilege Vulnerability https://www.aakashrahsi.online/post/cve-2026-24300 https://t.co/6SxYPQ3lX9

    Post summary

    A new Azure Front Door elevation‑of‑privilege vulnerability (CVE‑2026‑24300) is announced, with a link to a post for further information.

    0000039
    2 followersView on X
  • hi^^@collysucker
    Disclosure

    https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24300 Azure Front Door CVE-2026-24300 CVSS:3.1 9.8 / 8.5 Anyone additional information? #infosec #azure

    Post summary

    The text links to the MSRC update guide for CVE-2026-24300, providing the CVE identifier and CVSS scores but no further exploitation or remediation details.

    00000119
    220 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Microsoft Azure Front Door (CVE-2026-24300) https://vuldb.com/?id.344612

    Post summary

    A new vulnerability with increased severity was disclosed for Microsoft Azure Front Door, identified as CVE-2026-24300.

    00000108
    2.1K followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🔴 CVE-2026-24300 - Critical Azure Front Door Elevation of Privilege Vulnerability https://www.thehackerwire.com/vulnerability/CVE-2026-24300/ https://t.co/6Mv8pX7moo

    Post summary

    The tweet announces CVE‑2026‑24300 as a critical elevation‑of‑privilege vulnerability in Azure Front Door but offers no additional details, PoC, or patch information.

    00000127
    113 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_front_door---

Explore more