CVE-2026-26124General(microsoft / aci_confidential_containers)

LOWCVSS 6.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft aci_confidential_containers systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

'.../...//' in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-35CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aci_confidential_containers

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-06); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
aci_confidential_containers

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-03-06: 2Mentions · 2026-03-07: 2Mentions · 2026-03-27: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-07: 2Technical Details · 2026-03-27: 103-0603-0703-27
Signal classification3 categories
General
240.0%
Disclosure
240.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-062
General2
2026-03-072
Disclosure2
2026-03-271
Patch1
Full discourse5 posts
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 2026. 3. 7 Microsoft ACI 上の機密コンテナーの特権昇格の脆弱性 CVE-2026-26124 Security Vulnerability リリース日: Mar 6, 2026 最終更新日: Mar 7, 2026 - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26124

    Post summary

    Microsoft has announced a new privilege‑escalation vulnerability (CVE‑2026‑26124) affecting confidential containers on Azure Container Instances, with no evidence of PoC, exploit, or active exploitation.

    10100125
    89 followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    ☁️ Azure ACI Confidential Containers EoP (CVE-2026-23651 + CVE-2026-26124) Double priv-esc chain (CVSS 6.7 each) in confidential containers. Azure ACI users: Patch now. https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-march-2026/ #Azure #CVE

    Post summary

    Azure ACI users are urged to apply patches for two privilege escalation vulnerabilities, CVE-2026-23651 and CVE-2026-26124, each rated CVSS 6.7.

    0001075
    492 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 CVE-2026-26124 Security Vulnerability 影響: 特権の昇格 最大深刻度: 緊急 CVSS:3.1 6.7 / 6.0 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 悪用される可能性は低い https://x.com/kawn2020/status/2030112859146047548

    Post summary

    Microsoft CVE-2026-26124 is a privilege‑escalation vulnerability with emergency severity and low exploitation likelihood; no PoC, exploit code, patch, or active attacks are reported.

    1000079
    89 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-26124 Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-26124 ----- Traducción: CVE-2026-26124 Microsoft ACI Contenedores Confidenciales Vulnerabilidad de Elevación de Privilegios … http://infoflow.cloud`

    Post summary

    The post merely announces the existence of CVE-2026-26124 and links to the official CVE record; it contains no detailed technical or exploitation information.

    0000032
    56 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-26124 Microsoft ACI Confidential Containers Elevation of Privilege Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-26124

    Post summary

    A simple reference to the CVE record is provided, without any additional technical or operational context.

    00000192
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftaci_confidential_containers---

Explore more