Vulnerabilities Fixed in Microsoft Azure Components (NCSC-2026-0233) (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- Microsoft patched multiple Azure components.
- Critical CVEs: CVE-2026-57100 and CVE-2026-45499 with CVSS 9.9.
- Affected: OpenAI, Entra, Monitor Agent, CycleCloud, Spring Apps, AAD, Synapse.
- No user action required.
- NCSC threat rating: medium to high.
"The Dutch NCSC reports that Microsoft has fixed vulnerabilities across several Azure components, including the OpenAI agent and Entra provisioning. An attacker could exploit these for denial-of-service, security bypass, or privilege escalation. The most critical CVEs are CVE-2026-57100 (CVSS 9.9) and CVE-2026-45499 (CVSS 9.9). No user action is required as patches are applied centrally."
no comments yet.