CVE-2026-24302Disclosure(microsoft / azure_arc)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft azure_arc systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_arc

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-02-06); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
azure_arc

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-02-05: 1Mentions · 2026-02-06: 3Mentions · 2026-02-11: 1Mentions · 2026-04-14: 1Patch / Workaround · 2026-02-06: 1Technical Details · 2026-02-05: 1Technical Details · 2026-02-06: 3Technical Details · 2026-04-14: 102-0502-0602-1104-14
Signal classification3 categories
Disclosure
466.7%
General
116.7%
Patch
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-051
General1
2026-02-063
Disclosure2Patch1
2026-02-111
Disclosure1
2026-04-141
Disclosure1
Full discourse6 posts
  • kawn@kawn2020
    Patch

    #securityupdate #microsoft #定例外 2026. 2. 5 Azure Arc の特権の昇格の脆弱性 CVE-2026-24302 Security Vulnerability リリース日: Feb 5, 2026 - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24302

    Post summary

    The message announces Microsoft’s release of a patch for the Azure Arc privilege‑escalation vulnerability CVE‑2026‑24302, with a link to the official update guide. It serves as a vendor advisory rather than an exploit or active‑attack alert.

    10100161
    89 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-24302: HIGH] Azure Arc Elevation of Privilege Vulnerability#cve,CVE-2026-24302,#cybersecurity https://cvefind.com/CVE-2026-24302

    Post summary

    The tweet announces a high‑severity elevation‑of‑privilege vulnerability in Azure Arc (CVE‑2026‑24302) without providing PoC, exploit, patch, or active exploitation details.

    0101078
    583 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-24302 Azure Arc Elevation of Privilege Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-24302

    Post summary

    The entry only cites the CVE ID and a brief label of the vulnerability type, lacking any deeper technical, exploit, or mitigation details.

    00010251
    56.5K followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-24302 | Azure Arc Elevation of Privilege Vulnerability https://www.aakashrahsi.online/post/cve-2026-24302-1 https://t.co/KLI3uL4BRR

    Post summary

    The tweet announces CVE-2026-24302, an Azure Arc elevation of privilege vulnerability, and provides links to a blog post for further details.

    0000030
    1 followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-24302 | Azure Arc Elevation of Privilege Vulnerability https://www.aakashrahsi.online/post/cve-2026-24302 https://t.co/nApZV4IiEJ

    Post summary

    The tweet links to a blog post announcing CVE-2026-24302, an Azure Arc privilege‑elevation vulnerability, but provides no additional technical, exploit, or mitigation details.

    0000038
    2 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 CVE-2026-24302 Security Vulnerability 影響: 特権の昇格 最大深刻度: 緊急 CVSS:3.1 8.6 / 7.5 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 対象外 https://x.com/kawn2020/status/2019669526183571727

    Post summary

    A Microsoft privilege‑escalation vulnerability (CVE‑2026‑24302) is disclosed with emergency severity and CVSS scores, but no PoC, exploit code, or patch information is provided.

    0000061
    89 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_arc---

Explore more