Microsoft addresses critical security vulnerability in Azure environment

Attackers could have exploited vulnerabilities in Azure Arc, Azure Function, or Azure Front Door.

listen Print view
Blackout,Concept.,Emergency,Failure,Red,Light,In,Data,Center,With

Emergency in the data center

(Image: vchal/Shutterstock.com)

1 min. read

Microsoft's multi-cloud management solution Azure Arc, the serverless development environment Azure Functions, and the content delivery network (CDN) Azure Front Door were vulnerable. The technology company classifies the overall risk as critical.

In two cases (Azure Arc: CVE-2026-243012 "high"), (Azure Front Door: CVE-2026-24300 "critical"), attackers could have gained higher user privileges. After a successful attack on Azure Function, attackers would have had access to actually protected information (CVE-2026-21532 "high").

How attacks could occur in detail is currently unknown. In the security advisories for the vulnerabilities, linked under the CVE numbers in this article, Microsoft assures that they are not aware of any attacks at this time.

Videos by heise

The hardware and software manufacturer states that they have resolved the security issues server-side. Consequently, admins do not need to install any security patches, and instances are now protected from the described attack scenarios.

(des)

Don't miss any news – follow us on Facebook, LinkedIn or Mastodon.

This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.