White Rabbitx[verified]@TheRabbitPyPatch
The tweet announces CVE‑2026‑26148, a root‑escape vulnerability in the Azure AD SSH extension for Linux VMs with a CVSS of 8.1, and urges users to update the extension to apply the patch.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
CVE‑2026‑26148 was actively exploited by attackers to gain near‑global admin rights in Microsoft Entra ID through privilege escalation and impersonation. While technical details are provided, no patch or explicit workaround is offered.
CVE@CVEnewDisclosure
A new CVE, CVE‑2026‑26148, has been disclosed, describing a privilege‑escalation flaw in Azure Entra ID related to external initialization of trusted data.
The Hacker Wire@TheHackerWireDisclosure
A new high‑severity CVE‑2026‑26148 in Azure Entra ID is disclosed, describing a privilege escalation path via external initialization of trusted data stores.