ZeroHour

CVE-2026-26117

CVSS 3.1
7.8 high
EPSS
<1%p37
Published
()
Modified
Description

Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
arc enabled servers azure connected machine agent
Weakness
CWE-288
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.