CVE-2026-33105Disclosure(microsoft / azure_kubernetes_service)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft azure_kubernetes_service systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_kubernetes_service

Threat summary

  • Patch or workaround signal is available
  • 14 mentions across 5 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 13 signals
  • Disclosure: 9 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 9 mentions (2026-04-03); latest day: 1
  • 14 total mentions across 5 days

Affected systems

Vendors
Products
azure_kubernetes_service

1 version affected across 1 product

Deep dive

Activity timeline14 mentions / 5d
02579Mentions · 2026-04-03: 9Mentions · 2026-04-04: 1Mentions · 2026-04-06: 1Mentions · 2026-04-07: 2Mentions · 2026-04-10: 1Patch / Workaround · 2026-04-03: 2Patch / Workaround · 2026-04-04: 1Patch / Workaround · 2026-04-07: 1Technical Details · 2026-04-03: 9Technical Details · 2026-04-04: 1Technical Details · 2026-04-06: 1Technical Details · 2026-04-07: 204-0304-0404-0604-0704-10
Signal classification3 categories
Disclosure
964.3%
Patch
321.4%
General
214.3%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-04-039
Disclosure7General1Patch1
2026-04-041
Patch1
2026-04-061
Disclosure1
2026-04-072
Disclosure1Patch1
2026-04-101
General1
Full discourse14 posts
  • Firmis Labs@FirmisLabs
    Disclosure

    CVE-2026-33105 · NIST 10.0/10 https://nvd.nist.gov/vuln/detail/CVE-2026-33105

    Post summary

    The post references CVE-2026-33105 with a CVSS score of 10.0, but offers no additional details or evidence of exploitation.

    1000025
    1 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-33105: Azure Kubernetes Service Authorization Flaw - What It Means for Your Business and How to Respond https://hubs.li/Q04bm1qQ0

    Post summary

    The text only lists the CVE title and a link, offering no concrete details on exploitation, patching, or technical characteristics.

    0000038
    28 followersView on X
  • NCIIPC India@NCIIPC
    Patch

    #Microsoft released Security Update to address an Elevation of Privilege Vulnerability in Microsoft Azure Kubernetes Service. #CVE-2026-33105 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33105

    Post summary

    Microsoft has released a security update addressing an elevation‑of‑privilege flaw in Azure Kubernetes Service (CVE‑2026‑33105), with the patch information available via the provided link.

    00000107
    8.4K followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-33105 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability https://www.aakashrahsi.online/post/cve-2026-33105 https://t.co/hyjW7PNsAV

    Post summary

    A blog post announces the newly identified elevation of privilege vulnerability CVE-2026-33105 in Microsoft Azure Kubernetes Service, but no PoC, exploit, or patch details are provided.

    0000037
    1 followersView on X
  • Kwaza ICT@KwazaIct
    Patch

    CVE-2026-33105 is a critical vuln in Azure Kubernetes Service allowing privilege escalation. Immediate patching is crucial to secure your deployments. Don't delay! #Azure #Kubernetes

    Post summary

    The message focuses on the critical CVE-2026-33105 in Azure Kubernetes Service, urges immediate patching to mitigate privilege escalation, and provides basic technical details.

    0000062
  • CVE@CVEnew
    Disclosure

    CVE-2026-33105 Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-33105

    Post summary

    The notice reports the identification of CVE-2026-33105, describing an improper authorization flaw that permits privilege escalation within Azure Kubernetes Service.

    00000111
    56.9K followersView on X
  • Jason Abernathy@jlabernathy
    Disclosure

    Microsoft published CVE-2026-33105 in Azure Kubernetes Service today. CVSS 10.0. Improper authorization. Requires authenticated access - a low bar in enterprise environments with over-permissioned service accounts. If you run AKS and haven't applied Azure Update Manager patches yet, you're currently exposed. No editorial needed. #AzureKubernetes #Infosec

    Post summary

    Microsoft released CVE-2026-33105 for Azure Kubernetes Service, a high‑severity improper authorization flaw requiring authenticated access; users are urged to apply Azure Update Manager patches.

    0000046
    385 followersView on X
  • Vito Botta@vitobotta
    Patch

    Microsoft just disclosed CVE-2026-33105 - a critical CVSS 10.0 vulnerability in Azure Kubernetes Service. The flaw allows unauthenticated attackers to escalate privileges remotely over the network. No user interaction needed, low attack complexity. Microsoft has already patched it, but if you're running AKS you should verify your clusters are updated. The scope is "changed" meaning attackers could affect resources beyond their initial access - potentially crossing tenant boundaries. Definitely worth checking your AKS versions today.

    Post summary

    Microsoft disclosed CVE‑2026‑33105, a critical privilege‑escalation flaw in Azure Kubernetes Service, and has already released a patch; users should confirm their clusters are updated.

    0000082
    907 followersView on X
  • CTIWatch@ctiwatchcloud
    Disclosure

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-32213 | CVSS 10.0 🔴 CVE-2026-32871 | CVSS 10.0 🔴 CVE-2026-33105 | CVSS 10.0 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post delivers a concise announcement of three new zero‑day CVEs, each with a CVSS score of 10.0, without providing exploit details, mitigation or further technical depth.

    0000036
    5.6K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-33105 📊 Severity: 10.0 🚨 Risk Level: Critical 🧩 Affects: Microsoft Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33105 #CVE-2026-33105 #CVE #Critical #Microsoft #CyberSecurity #InfoSec https://t.co/zCuVZU2YYt

    Post summary

    The tweet announces CVE-2026-33105 affecting Microsoft with a severity score of 10.0, but offers no technical, exploitation, or mitigation details.

    0000042
    123 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33105 - Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability Intel Report: https://ift.tt/xsnXCSR

    Post summary

    A newly reported CVE (2026-33105) affecting Azure Kubernetes Service’s elevation of privilege is highlighted, with only an intel report link and no exploitation, PoC, or patch info.

    0000069
    282 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33105 - Critical Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. https://www.thehackerwire.com/vulnerability/CVE-2026-33105/ https://t.co/DitXTnrY8y

    Post summary

    A new critical vulnerability (CVE-2026-33105) in Azure Kubernetes Service has been disclosed, describing improper authorization that can lead to privilege escalation; no PoC, exploit, or patch details are provided.

    0000060
    160 followersView on X
  • dbugs@ptdbugs
    Disclosure

    Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability CVE: CVE-2026-33105 PT ID: PT-2026-29906 Vendor: Microsoft Product: Azure Kubernetes Service CVSS: 10.0 Credits: n/a Description: Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-33105 • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-33105 #dbugs_vuln

    Post summary

    Microsoft Azure Kubernetes Service has a high‑severity elevation of privilege vulnerability (CVE-2026-33105) described as improper authorization; no exploitation or patch details are given in the text.

    0000098
    768 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-33105: CRITICAL] Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.#cve,CVE-2026-33105,#cybersecurity https://cvefind.com/CVE-2026-33105

    Post summary

    The tweet announces a critical improper authorization flaw in Microsoft Azure Kubernetes Service that could enable an unauthenticated attacker to elevate privileges over the network; it contains no PoC, exploit, or patch information.

    0000058
    610 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_kubernetes_service---

Explore more