CVE-2026-45480Disclosure(microsoft / azure_active_directory)

MEDIUMCVSS 10.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft azure_active_directory systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_active_directory

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-20); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
azure_active_directory

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-06-19: 1Mentions · 2026-06-20: 2Mentions · 2026-06-23: 1Active Exploitation · 2026-06-20: 1Patch / Workaround · 2026-06-20: 1Patch / Workaround · 2026-06-23: 1Technical Details · 2026-06-19: 1Technical Details · 2026-06-20: 1Technical Details · 2026-06-23: 106-1906-2006-23
Signal classification3 categories
Disclosure
250.0%
Active Exploitation
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-191
Disclosure1
2026-06-202
Active Exploitation1Disclosure1
2026-06-231
Patch1
Full discourse4 posts
  • SecAlerts@SecAlertsCo
    Patch

    🔑 Azure Active Directory has a critical flaw. CVE-2026-45480 allows an unauthenticated attacker to elevate privileges over the network — no interaction needed. CVSS 10. Patch now if Azure AD is in your stack. #Microsoft #infosec https://secalerts.co/vulnerability/CVE-2026-45480?utm_campaign=x https://t.co/bXKD9J0KjG

    Post summary

    CVE‑2026‑45480 is a critical privilege‑escalation flaw in Azure AD with a CVSS 10 score; a patch is currently available and should be applied immediately if Azure AD is used.

    00000111
    842 followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    CVE-2026-45480 (CVSS 10.0): improper authentication in Azure Active Directory allows network privilege escalation. Azure AD admins should check Microsoft updates now. https://nvd.nist.gov/vuln/deta… via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/NvDOTeYorI

    Post summary

    The tweet announces the high‑severity Azure AD vulnerability CVE‑2026‑45480 and urges admins to apply Microsoft updates.

    0000052
    92 followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting Microsoft Azure (CVE-2026-45480) https://vuldb.com/vuln/372321/cti

    Post summary

    The text indicates that CVE-2026-45480 is currently being targeted in offensive operations against Microsoft Azure, but it lacks details on technical exploitability, PoCs, patches, or false positive status.

    0000065
    2.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-45480 Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-45480

    Post summary

    The statement announces a new Azure AD authentication flaw that permits attackers to elevate privileges across a network.

    00000222
    57.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_active_directory---

Explore more