CVE-2026-32169Disclosure(microsoft / azure_cloud_shell)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft azure_cloud_shell systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_cloud_shell

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 9 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 6d ago at 2 mentions (2026-03-19); latest day: 1
  • 11 total mentions across 7 days

Affected systems

Vendors
Products
azure_cloud_shell

1 version affected across 1 product

Deep dive

Activity timeline11 mentions / 7d
01122Mentions · 2026-03-19: 2Mentions · 2026-03-20: 1Mentions · 2026-03-22: 2Mentions · 2026-03-23: 2Mentions · 2026-03-24: 2Mentions · 2026-03-31: 1Mentions · 2026-04-15: 1Patch / Workaround · 2026-03-23: 2Patch / Workaround · 2026-03-24: 1Patch / Workaround · 2026-04-15: 1Technical Details · 2026-03-19: 2Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 2Technical Details · 2026-03-23: 2Technical Details · 2026-03-24: 1Technical Details · 2026-04-15: 103-1903-2003-2203-2303-2403-3104-15
Signal classification3 categories
Disclosure
763.6%
Patch
327.3%
General
19.1%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-192
Disclosure2
2026-03-201
Disclosure1
2026-03-222
Disclosure2
2026-03-232
Patch2
2026-03-242
Disclosure1Patch1
2026-03-311
General1
2026-04-151
Disclosure1
Full discourse11 posts
  • dbugs@ptdbugs
    Disclosure

    Azure Cloud Shell Elevation of Privilege Vulnerability CVE: CVE-2026-32169 PT-Identifier: PT-2026-26363 Vendor: Microsoft Product: Azure Cloud Shell CVSS: 10.0 Credits: n/a Description: Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-32169 • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32169 #dbugs_vuln

    Post summary

    The post announces a CVE‑2026‑32169 SSRF vulnerability in Azure Cloud Shell with a CVSS score of 10.0, highlighting its privilege‑escalation potential, but does not provide a PoC, exploit, or evidence of active exploitation.

    0102188
    649 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #microsoft #定例外 2026. 3.19 Azure Cloud Shell Elevation of Privilege Vulnerability CVE-2026-32169 Security Vulnerability リリース日: - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32169

    Post summary

    The tweet announces a Microsoft security update for CVE‑2026‑32169 and links to the vendor’s advisory, indicating a patch is available but providing no PoC, exploit code, or evidence of active exploitation.

    1010080
    88 followersView on X
  • kawn@kawn2020
    Disclosure

    #securityupdate #microsoft #定例外 CVE-2026-32169 Security Vulnerability 影響: 特権の昇格 最大深刻度: 緊急 CVSS:3.1 10.0 / 8.7 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 対象外 https://x.com/kawn2020/status/2036267904430485615

    Post summary

    The tweet announces CVE-2026-32169, detailing it as a privilege‑escalation flaw with emergency severity and scores, but provides no PoC, exploit, or patch information.

    1000038
    88 followersView on X
  • z3n@zench4n
    Patch

    Azure Cloud Shell SSRF (CVE-2026-32169) is a reminder to lock down your cloud metadata endpoint. Assume compromise. Least privilege is key.

    Post summary

    The text highlights an SSRF vulnerability in Azure Cloud Shell (CVE-2026-32169) and advises locking down the cloud metadata endpoint as a mitigation, rather than discussing exploitation or patch availability.

    1000014
    1.5K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-32169: CRITICAL] Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network.#cve,CVE-2026-32169,#cybersecurity https://cvefind.com/CVE-2026-32169

    Post summary

    The post announces a critical SSRF vulnerability in Azure Cloud Shell that can lead to privilege escalation, with no active exploitation, patches, or PoC evidence provided.

    0001064
    603 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32169 - Critical Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network. https://www.thehackerwire.com/vulnerability/CVE-2026-32169/ https://t.co/YORCRypmSi

    Post summary

    The tweet announces a critical SSRF vulnerability (CVE-2026-32169) in Azure Cloud Shell that could lead to privilege escalation, without indicating PoC, exploit, mitigation, or active exploitation.

    0001063
    137 followersView on X
  • AiSoloStudio@aisolostudio
    Disclosure

    Azure Cloud ShellにCVSS 10.0のSSRF(CVE-2026-32169)。Django 4.2/5.2/6.0にASGIヘッダー偽装やDoSなど5件の修正リリース。Vite開発サーバーにも任意ファイル読み取り3件。npm simple-gitはRCE(9.8) #security #セキュリティ #CVE #脆弱性 https://tsumikasane.net/security/daily/2026-04-15/

    Post summary

    The post announces a new Azure Cloud Shell SSRF vulnerability (CVE‑2026‑32169) with a CVSS of 10.0, lists patch releases for Django, Vite, and simple‑git, and gives concise technical details but no proof‑of‑concept or active exploitation evidence.

    0000058
    5 followersView on X
  • Aakash Rahsi@rahsi_aaka
    General

    CVE-2026-32169 | Azure Cloud Shell Elevation of Privilege Vulnerability https://www.aakashrahsi.online/post/cve-2026-32169 https://t.co/j24i8BGBfA

    Post summary

    The post references CVE-2026-32169 and provides URLs, but offers no additional information regarding exploitation, patches, or technical details.

    0000034
    1 followersView on X
  • NCIIPC India@NCIIPC
    Patch

    #Microsoft released Security Update to address an Elevation of Privilege Vulnerability in #Azure Cloud Shell. #CVE-2026-32169 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32169

    Post summary

    The post announces Microsoft’s security update for CVE‑2026‑32169, indicating a patch is available for an elevation‑of‑privilege flaw in Azure Cloud Shell.

    00000103
    8.4K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-32169 Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-32169 ----- Traducción: CVE-2026-32169 SSRF (solicitud de servidor a servidor) en Azu… http://infoflow.cloud`

    Post summary

    The post announces an SSRF vulnerability in Azure Cloud Shell that could let attackers elevate privileges, providing technical details and a CVE link but no proof of exploitation or fixes.

    0000038
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32169 Server-side request forgery (ssrf) in Azure Cloud Shell allows an unauthorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-32169

    Post summary

    The text announces CVE‑2026‑32169, a server‑side request forgery vulnerability in Azure Cloud Shell that can allow an unauthorized attacker to elevate privileges over a network.

    00000223
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_cloud_shell---

Explore more