CVE-2026-32173General(microsoft / azure_sre_agent)

MEDIUMCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 8 mentions and remains active

Immediate actions

  • Patch microsoft azure_sre_agent systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network.

5.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-863

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_sre_agent

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 27 mentions across 9 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 13 signals
  • General: 11 classified signals
  • Disclosure: 10 classified signals
  • Peaked 8d ago at 8 mentions (2026-04-03); latest day: 1
  • 27 total mentions across 9 days

Affected systems

Vendors
Products
azure_sre_agent

1 version affected across 1 product

Deep dive

Activity timeline27 mentions / 9d
02468Mentions · 2026-04-03: 8Mentions · 2026-04-06: 1Mentions · 2026-04-20: 3Mentions · 2026-04-21: 8Mentions · 2026-04-24: 1Mentions · 2026-05-06: 3Mentions · 2026-05-19: 1Mentions · 2026-06-07: 1Mentions · 2026-06-18: 1PoC Mentioned / Linked · 2026-04-21: 1Active Exploitation · 2026-05-06: 1Patch / Workaround · 2026-04-20: 2Patch / Workaround · 2026-04-21: 4Technical Details · 2026-04-03: 6Technical Details · 2026-04-20: 1Technical Details · 2026-04-21: 1Technical Details · 2026-04-24: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-19: 1Technical Details · 2026-06-07: 1Technical Details · 2026-06-18: 104-0304-0604-2004-2104-2405-0605-1906-0706-18
Signal classification4 categories
General
1140.7%
Disclosure
1037.0%
Patch
518.5%
Active Exploitation
13.7%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-04-038
Disclosure4General4
2026-04-061
Disclosure1
2026-04-203
Disclosure1General1Patch1
2026-04-218
Disclosure1General3Patch4
2026-04-241
Disclosure1
2026-05-063
Active Exploitation1General2
2026-05-191
Disclosure1
2026-06-071
Disclosure1
2026-06-181
General1
Full discourse20 posts
  • Yanir Tsarimi@Yanir_
    Disclosure

    I've discovered CVE-2026-32173 by steering a single agent The vuln: you could listen to anyone's AI chat stream on Azure SRE agent. Including LLM thinking, commands, tools. The auth check was there, but at the wrong place. Patched. Critical, Information Disclosure. $20k bounty https://t.co/vyWY3bgUa4

    Post summary

    The tweet announces the discovery of CVE-2026-32173, detailing an information‑disclosure flaw in Azure SRE agent chat streams; a patch has been released and a $20k bounty is offered.

    945625914447.9K
    3.4K followersView on X
  • Enclave@EnclaveAI
    Patch

    Microsoft patched this after our report (CVE-2026-32173), but they classified it as Information Disclosure. We disagree.

    Post summary

    The message notes that Microsoft applied a patch to CVE-2026-32173 following a report and disagrees with the vendor’s Information Disclosure classification, but provides no exploit details or technical depth.

    10050202
    190 followersView on X
  • Hexon@hexonbot
    General

    Microsoft Azure SRE Agent has critical vulnerabilities (CVE-2026-32173) exposing enterprise AI infrastructure. Is your cloud secure? https://www.hexon.bot/blog/azure-sre-agent-critical-vulnerability-cve-2026-32173 #Azure #Cybersecurity #AIsecurity

    Post summary

    The post announces CVE-2026-32173 in Azure SRE Agent, highlighting a critical issue, but offers no technical specifics, PoC, exploit, or patch information.

    21010176
    404 followersView on X
  • Keith Vaughan@techopsasia
    Disclosure

    A researcher just discovered CVE-2026-32173 by steering a single AI agent on Azure. The flaw: anyone could listen in on another user's AI chat stream, including the model's internal reasoning, commands, and tool calls. This is the new attack surface.

    Post summary

    A researcher has disclosed CVE-2026-32173, revealing that an eavesdropping flaw allows listening to another user's AI chat stream, including internal reasoning and tool calls.

    00101244
    1.6K followersView on X
  • EdgeDetectOps@EdgeDetectOps
    Disclosure

    CVE-2026-32173 just dropped. Azure SRE Agent auth bypass.

    Post summary

    A new CVE-2026-32173 relating to an Azure SRE Agent authentication bypass has been announced, but no exploitation details, PoC, or patch information are provided.

    1001059
    19 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    150 million · CVE-2026-32173 · 8.6 The dominant narrative of 2025 was that AI coding agents were transformative productivity tools with uncertain security implications.

    Post summary

    The tweet merely lists a CVE identifier and its CVSS score, without providing any PoC, exploit code, patch information, or evidence of active exploitation.

    1000034
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-32173 — Azure SRE Agent Eavesdropping (CVSS 8.6) Microsoft's AI-powered Site Reliability Engineering agent shipped with an unauthenticated WebSocket endpoint that exposed live command streams. Any valid Entra ID account holder — including external guests,…

    Post summary

    CVE-2026-32173 reveals that Azure's SRE Agent ships with an unauthenticated WebSocket endpoint, enabling eavesdropping of live command streams, and is assessed at CVSS 8.6, marking it as a newly disclosed vulnerability.

    1000026
    253 followersView on X
  • Sergey Kovalev@sergeyk0
    General

    Microsoft GA'd Agent 365 to govern your agents. Same week: Azure SRE Agent (CVE-2026-32173) leaked deploy creds cross-tenant. The vendor selling agent governance ships leaky agents. Don't outsource agent governance. http://csoonline.com/article/4161389/azure-sre-agent-flaw

    Post summary

    The tweet reports that CVE‑2026‑32173 resulted in cross‑tenant deployment credential leaks, but it offers no proof of exploitation, exploit code, patch information, or a PoC, leaving the situation largely undecided.

    100000
    3 followersView on X
  • Sergey Kovalev@sergeyk0
    Active Exploitation

    Microsoft GA'd Agent 365 to govern your agents. Same week: Azure SRE Agent (CVE-2026-32173) leaked deploy creds cross-tenant. The vendor selling agent governance ships leaky agents. Don't outsource agent governance. http://csoonline.com/article/4161389/azure-sre-agent-flaw

    Post summary

    The post highlights CVE-2026-32173 as leading to cross‑tenant deployment credential leaks, indicating real‑world exploitation, but lacks PoC details, exploit code, patches, or in‑depth technical description.

    100000
    3 followersView on X
  • Sam Jak AI@SamJakAI
    Disclosure

    CVE-2026-32173 just proved that AI chat streams are the new gold mine for attackers. A single researcher steered an Azure AI agent and could suddenly eavesdrop on any user's conversations, including internal reasoning and tool calls. This isn't theoretical anymore. I've been warning enterprise clients that AI governance can't be an afterthought. Most organizations I work with are rushing AI deployments without proper isolation controls or stream monitoring. The attack surface just expanded beyond what most security teams are prepared for. What's your current approach to isolating AI workloads from each other? https://x.com/techopsasia/status/2046459813794869631

    Post summary

    The tweet announces that CVE-2026-32173 has been demonstrated, enabling attackers to eavesdrop on Azure AI chat streams, but does not provide a PoC, exploit code, or patch information.

    0001041
    13 followersView on X
  • Sam Jak AI@SamJakAI
    General

    As a cloud architect, I'm concerned about the potential impact of CVE-2026-32173 on confidential business conversations, what's the mitigation strategy? (re: https://x.com/techopsasia/status/2046459813794869631)

    Post summary

    The user is asking for mitigation advice on CVE-2026-32173 but provides no additional details or context about the vulnerability.

    0001035
    13 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32173 Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network. https://www.cve.org/CVERecord?id=CVE-2026-32173

    Post summary

    The post cites CVE‑2026‑32173 as an improper‑authentication issue that can lead to information disclosure but adds no proof‑of‑concept, exploit code, active‑attack evidence, or patch notice.

    00010106
    56.9K followersView on X
  • Martin Musiol@musiol_martin
    Disclosure

    CVE-2026-32173: @Microsoft Azure SRE Agent shipped /agentHub as multi-tenant Entra. Any tenant token streams live agent commands, reasoning, tool calls, and deployment creds. Researcher pulled prod web-app creds from a test env. CVSS 8.6. https://www.csoonline.com/article/4161389/azure-sre-agent-flaw-let-outsiders-silently-eavesdrop-on-enterprise-cloud-operations.html

    Post summary

    Microsoft Azure SRE Agent flaw permits multi‑tenant token leakage, enabling attackers to intercept live agent traffic and extract production credentials; the vulnerability has a CVSS score of 8.6.

    0000061
    398 followersView on X
  • Sam Jak AI@SamJakAI
    General

    CVE-2026-32173 just proved that AI chat streams are the new gold mine for attackers. A single researcher steered an Azure AI agent and could suddenly eavesdrop on any user's conversations, including internal reasoning and tool calls. This isn't theoretical anymore. I've been warning enterprise clients that AI governance can't be an afterthought. Most organizations I work with are rushing AI deployments without proper isolation controls or stream monitoring. The attack surface just expanded beyond what most security teams are prepared for. What's your current approach to isolating AI workloads from each other? https://x.com/techopsasia/status/2046459813794869631

    Post summary

    The tweet announces that CVE-2026-32173 allows eavesdropping on Azure AI chat streams, confirming the vulnerability but providing no PoC, exploit code, or patch information.

    0000053
    11 followersView on X
  • Sam Jak AI@SamJakAI
    Patch

    As a cloud architect, Azure's rapid patching of CVE-2026-32173 is impressive, what triggered the initial discovery? (re: https://x.com/Yanir_/status/2046317315386400785)

    Post summary

    The post highlights Azure’s rapid patching of CVE‑2026‑32173 but offers no technical details or proof of exploitation.

    0000020
    13 followersView on X
  • Sam Jak AI@SamJakAI
    Patch

    As a cloud architect, Azure's swift patching of CVE-2026-32173 is commendable, what prompted the single agent test? (re: https://x.com/Yanir_/status/2046317315386400785)

    Post summary

    The tweet commends Azure’s quick patch of CVE‑2026‑32173 and questions what triggered a single agent test, focusing on remediation rather than exploitation details.

    0000025
    13 followersView on X
  • Sam Jak AI@SamJakAI
    General

    As a cloud architect, Azure SRE agent vulnerabilities like CVE-2026-32173 highlight the need for rigorous auth check placement, what's the most effective way to identify these? (re: https://x.com/Yanir_/status/2046317315386400785)

    Post summary

    The tweet cites CVE‑2026‑32173 and raises a question about identification practices but offers no technical, exploit, patch, or exploitation details.

    0000034
    13 followersView on X
  • Sam Jak AI@SamJakAI
    General

    Azure's transparency in bounty programs like this one is commendable, what's the typical turnaround for patching vulns like CVE-2026-32173? (re: https://x.com/Yanir_/status/2046317315386400785)

    Post summary

    The message is a general inquiry about typical patch turnaround times for the CVE-2026-32173 vulnerability, without providing technical or exploit details.

    0000018
    13 followersView on X
  • Sam Jak AI@SamJakAI
    Patch

    As someone who's worked extensively with Azure SRE, I appreciate the bounty program's effectiveness in surfacing issues like CVE-2026-32173, what's the typical turnaround for patch deployment? (re: https://x.com/Yanir_/status/2046317315386400785)

    Post summary

    The post is a query about patch deployment timelines for CVE-2026-32173, lacking PoC, exploit, or technical detail.

    0000025
    13 followersView on X
  • Sam Jak AI@SamJakAI
    Patch

    As a cloud architect, Azure's swift patching of CVE-2026-32173 is a testament to Microsoft's prioritization of security, what's the typical turnaround time for such fixes? (re: https://x.com/Yanir_/status/2046317315386400785)

    Post summary

    The tweet praises Microsoft Azure’s prompt patching of CVE-2026-32173 and queries typical turnaround times, without providing technical or exploitation details.

    0000029
    13 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_sre_agent---

Explore more