ZeroHour

CVE-2026-65816

large1

Unauthenticated Privilege Elevation Flaw in Microsoft Azure Arc

CVSS 3.1
10.0 critical
EPSS
<1%p43
Published
()
Modified
AI analysis

Microsoft Azure Arc contains a use of incorrectly-resolved name or reference (CWE-706) that allows an unauthorized, unauthenticated attacker to elevate privileges over a network. The flaw is triggered through network access alone, with no privileges, user interaction, or complex conditions required, as reflected in its maximum CVSS 3.1 score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). The scope-changed metric indicates the attack crosses a security boundary, so an attacker who reaches the vulnerable component could gain elevated privileges with high impact on confidentiality, integrity, and availability. Organizations that have enrolled on-premises or multicloud resources into Azure Arc are affected; the source data provides no specific affected version ranges, and the CPE product entry also references Azure Web Apps while the description names Azure Arc. There is currently no known public proof-of-concept, the issue is not in CISA KEV, and EPSS assigns a 0.5% 30-day exploitation probability (43rd percentile), indicating no confirmed in-the-wild exploitation.

What to do: No fixed version numbers are included in the source data, so consult Microsoft's advisory and the September 2026 Patch Tuesday release for the Azure Arc update and apply it promptly when published. In the meantime, inventory Azure Arc-enabled servers and other enrolled resources, restrict network exposure of Arc agent and management endpoints to trusted management paths, and monitor Microsoft's advisory for changes to exploitation status. Given the maximum CVSS score but no PoC or KEV listing yet, treat this as a high-priority patch rather than an emergency, and escalate if Microsoft confirms active exploitation.

Affected
Microsoft Azure Arc
Microsoft Azure Web Apps (listed in CPE product data; description names Azure Arc)
Estimated exposure
large≈ hundreds of thousands of Arc-enrolled machines across enterprise tenants (deployment-pattern estimate; exact counts not in source data) — Azure Arc is a hybrid/multicloud management service broadly adopted by Microsoft's enterprise customer base, with each enrollment typically spanning many connected servers, so the plausible affected population is on the order of 100,000+…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Vendors
microsoft
Products
azure web apps
Weakness
CWE-706
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

September 2026 Patch Tuesday forecast: All we need is more time

September 2026 Patch Tuesday forecast expects record CVE volume after August's 398 fixes, with SharePoint flaws CVE-2026-55040 and CVE-2026-63520 actively exploited.

This Patch Tuesday forecast column notes August 2026 Patch Tuesday was the second largest ever with 398 resolved CVEs, yet only one was confirmed actively exploited. SharePoint flaws CVE-2026-55040 and CVE-2026-63520 are being chained for authentication bypass and remote code execution in active attacks against unpatched servers. Microsoft Defender's ShieldBreak elevation of privilege flaw (CVE-2026-69414) is publicly disclosed with PoC code and a fix is expected, while Chrome CVE-2026-85046 was reported exploited in the wild. Several products, including Windows 11 24H2 Home/Pro and Exchange Server 2016/2019 ESU, reach end of support in October 2026.

Help Net Security · 6d agoAdvisory in the wildCVE-2026-55040CVE-2026-63520CVE-2026-62911+5 CVEs1