Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-58275: Azure DNS Unauthorized Privilege Escalation
CVE-2026-58275 · published 2 months ago
Summary
An attacker can gain elevated access to Azure DNS, compromising network security. This is a serious concern because it allows unauthorized access to sensitive information and resources. Azure customers should update their DNS configurations and ensure proper authorization is in place to mitigate this risk.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | azure dns | - |
| microsoft | azure_dns |
All versions
cpe:2.3:a:microsoft:azure_dns:-:*:*:*:*:*:*:* |
Original advisory text
Azure DNS Elevation of Privilege Vulnerability
Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58275 vendor-advisory patch
Severity
10.0
Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-862Missing Authorization
Timeline
Published24 Jul 2026
Updated27 Sep 2026
First seen24 Jul 2026
Track software like this
Free during beta