AI analysis
Microsoft Azure Arc contains a use of incorrectly-resolved name or reference (CWE-706) that allows an unauthorized, unauthenticated attacker to elevate privileges over a network. The flaw is triggered through network access alone, with no privileges, user interaction, or complex conditions required, as reflected in its maximum CVSS 3.1 score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). The scope-changed metric indicates the attack crosses a security boundary, so an attacker who reaches the vulnerable component could gain elevated privileges with high impact on confidentiality, integrity, and availability. Organizations that have enrolled on-premises or multicloud resources into Azure Arc are affected; the source data provides no specific affected version ranges, and the CPE product entry also references Azure Web Apps while the description names Azure Arc. There is currently no known public proof-of-concept, the issue is not in CISA KEV, and EPSS assigns a 0.5% 30-day exploitation probability (43rd percentile), indicating no confirmed in-the-wild exploitation.
What to do: No fixed version numbers are included in the source data, so consult Microsoft's advisory and the September 2026 Patch Tuesday release for the Azure Arc update and apply it promptly when published. In the meantime, inventory Azure Arc-enabled servers and other enrolled resources, restrict network exposure of Arc agent and management endpoints to trusted management paths, and monitor Microsoft's advisory for changes to exploitation status. Given the maximum CVSS score but no PoC or KEV listing yet, treat this as a high-priority patch rather than an emergency, and escalate if Microsoft confirms active exploitation.
Affected
| Microsoft Azure Arc | — |
| Microsoft Azure Web Apps (listed in CPE product data; description names Azure Arc) | — |
Estimated exposure
large≈ hundreds of thousands of Arc-enrolled machines across enterprise tenants (deployment-pattern estimate; exact counts not in source data) — Azure Arc is a hybrid/multicloud management service broadly adopted by Microsoft's enterprise customer base, with each enrollment typically spanning many connected servers, so the plausible affected population is on the order of 100,000+…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.