CVE-2026-69555Patch(microsoft / azure_arc)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft azure_arc systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_arc

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-08-21); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
azure_arc

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-08-21: 1Mentions · 2026-08-23: 1Mentions · 2026-08-26: 1Patch / Workaround · 2026-08-23: 1Patch / Workaround · 2026-08-26: 1Technical Details · 2026-08-21: 1Technical Details · 2026-08-23: 1Technical Details · 2026-08-26: 108-2108-2308-26
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-08-211
Disclosure1
2026-08-231
Patch1
2026-08-261
Patch1
Full discourse3 posts
  • BT Haberler@BTHaberler
    Patch

    Microsoft, Entra ID Açığıyla Birlikte Azure Arc, Exchange Online ve Apache Cassandra'da Dört Kritik Açık Daha Kapattı! Daha önce duyurduğumuz Entra ID'deki CVSS 10.0 puanlı uzaktan kod çalıştırma açığı CVE-2026-69836 ile aynı güvenlik döngüsünde, Microsoft'un Azure Arc, Exchange Online ve Apache Cassandra'da dört kritik açık daha kapattığı ortaya çıktı. • Azure Arc'ta CVE-2026-65816 ve CVE-2026-69555 olmak üzere iki ayrı yetkisiz uzaktan yetki yükseltme açığı, Exchange Online'da ise CVE-2026-65801 kodlu benzer bir yetki yükseltme açığı bulunuyor. • Apache Cassandra'daki CVE-2026-65770 ise uzaktan keyfi kod çalıştırılmasına izin veriyor; Microsoft, bu beş açığın hiçbiri için şu ana kadar kamuya açık bir istismar kodu bulunmadığını belirtti. Tek bir güvenlik döngüsünde kimlik yönetimi, hibrit bulut yönetimi, e-posta ve veritabanı katmanlarını aynı anda etkileyen beş kritik açığın ortaya çıkması, Microsoft'un bulut ekosisteminin ne kadar birbirine bağlı ve geniş bir saldırı yüzeyine sahip olduğunu gösteriyor. #SiberGüvenlik #Microsoft #Azure

    Post summary

    Microsoft closed five critical vulnerabilities across Azure Arc, Exchange Online, and Apache Cassandra, providing patches without any publicly available exploits, emphasizing mitigation steps.

    0000046
    39 followersView on X
  • SecureChap@SecureChap
    Patch

    Unauth RCE in Microsoft Entra ID via deserialization of untrusted data. Attackers send crafted objects over the network with no credentials required to gain code execution. CVE-2026-69836 was found by Robert Fitzpatrick and fixed on August 21 2026. An early advisory wrongly flagged active exploitation; Microsoft corrected the record the following day. Three more unauth remote privilege escalations shipped the same day. CVE-2026-65816 and CVE-2026-69555 hit Azure Arc, CVE-2026-65801 affects Exchange Online, and CVE-2026-65770 impacts Azure Managed Instance for Apache Cassandra. Microsoft states no public exploits exist for the August fixes and no customer action is required. CISA added the separate Windows IKE RCE to its actively exploited list on or before the same date.

    Post summary

    Microsoft released a fix for CVE-2026-69836 and related vulnerabilities on August 21, 2026, clarified that no public exploits exist, and corrected earlier claims of active exploitation.

    00000173
    164 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-69555 Azure Arc Authorization Flaw Enables Privilege Escalation Over Network https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-69555

    Post summary

    The text announces CVE‑2026‑69555, highlighting an Azure Arc authorization flaw that enables network‑based privilege escalation, but provides no PoC, exploit code, patches, or evidence of active exploitation.

    00000101
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_arc---

Explore more