CVE-2026-26148Disclosure(microsoft / azure_ad_ssh_login_extension_for_linux)

MEDIUMCVSS 8.1 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft azure_ad_ssh_login_extension_for_linux systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-454

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_ad_ssh_login_extension_for_linux

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-03-10); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
azure_ad_ssh_login_extension_for_linux

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-10: 1Mentions · 2026-03-16: 1Mentions · 2026-03-27: 1Mentions · 2026-04-28: 1Active Exploitation · 2026-04-28: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-27: 1Technical Details · 2026-04-28: 103-1003-1603-2704-28
Signal classification3 categories
Disclosure
250.0%
Patch
125.0%
Active Exploitation
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-101
Disclosure1
2026-03-161
Disclosure1
2026-03-271
Patch1
2026-04-281
Active Exploitation1
Full discourse4 posts
  • White Rabbitx@TheRabbitPy
    Patch

    🐧 Azure AD SSH extension root esc (CVE-2026-26148) Linux VM extension flaw → full root (CVSS 8.1). AAD-integrated Linux VMs: Update extension ASAP. https://www.thezdi.com/blog/2026/3/10/the-march-2026-security-update-review #Linux #CVE

    Post summary

    The tweet announces CVE‑2026‑26148, a root‑escape vulnerability in the Azure AD SSH extension for Linux VMs with a CVSS of 8.1, and urges users to update the extension to apply the patch.

    0001047
    492 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26148 External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-26148

    Post summary

    A new CVE, CVE‑2026‑26148, has been disclosed, describing a privilege‑escalation flaw in Azure Entra ID related to external initialization of trusted data.

    00001190
    56.7K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited Microsoft's Agent ID Administrator role to take ownership of high-privilege Service Principals, escalating to near-Global Admin access. The vulnerability (CVE-2026-26148) enabled lateral movement across tenant resources through impersonation. Runtime identity controls help limit such privilege escalation chains. #IdentitySecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/microsoft-entra-id-agent-id-administrator-role-privilege-escalation-2026

    Post summary

    CVE‑2026‑26148 was actively exploited by attackers to gain near‑global admin rights in Microsoft Entra ID through privilege escalation and impersonation. While technical details are provided, no patch or explicit workaround is offered.

    0000048
    1.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-26148 - High External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally. https://www.thehackerwire.com/vulnerability/CVE-2026-26148/ https://t.co/l656mXrWWq

    Post summary

    A new high‑severity CVE‑2026‑26148 in Azure Entra ID is disclosed, describing a privilege escalation path via external initialization of trusted data stores.

    0000045
    133 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_ad_ssh_login_extension_for_linux---

Explore more