AI analysis
Microsoft Azure Arc (CVE-2026-62895) contains a privilege elevation flaw caused by a permissive cross-domain policy that trusts untrusted domains, mapped by Microsoft to CWE-942 (permissive cross-domain policy with untrusted domains), CWE-1390 (weak authentication) and CWE-89 (SQL injection). An unauthenticated attacker can exploit it over a network, with CVSS scoring indicating some user interaction is required (AV:N/AC:L/PR:N/UI:R), by abusing the overly permissive cross-domain trust to elevate privileges, with high impact on confidentiality, integrity and availability (CVSS 3.1: 8.8 High). Any organization using Azure Arc to manage hybrid or multi-cloud resources is potentially affected. There is no evidence of exploitation in the wild, no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.7% probability of exploitation in the next 30 days (52nd percentile). Microsoft addressed the flaw as part of its September 2026 Patch Tuesday release, which fixed 966 flaws including 2 zero-days.
What to do: Apply Microsoft's September 2026 Patch Tuesday updates for Azure Arc across all Arc-enabled infrastructure, prioritizing environments where unauthenticated network users can reach Arc-connected resources. The available data does not include fixed version or KB details, so consult the Microsoft advisory for CVE-2026-62895 to identify the patched build for your components. In the interim, review and tighten the domains Azure Arc trusts in cross-domain policies and treat any unauthenticated network access to Arc-managed resources as a privilege-elevation risk.
Estimated exposure
masslikely hundreds of thousands to millions of managed servers across Azure Arc estates (adoption-based estimate; no counts in source data) — Azure Arc is a mainstream Microsoft hybrid-cloud management service deployed by large enterprises to govern on-premises and multi-cloud server estates, so deployments plausibly number in the hundreds of thousands to millions of servers,…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.