Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-65816: Azure Arc lets attackers gain higher permissions

CVE-2026-65816 · published 14 days ago
Summary

Azure Arc, the tool that links on‑premise resources to Azure, has a flaw that could let an outsider raise their access level across the network. This could expose sensitive data or allow changes to systems. Install Microsoft’s latest security update and review your Azure Arc permissions right away.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
microsoft azure web apps -
microsoft azure_web_apps All versions
cpe:2.3:a:microsoft:azure_web_apps:-:*:*:*:*:*:*:*
Original advisory text
Azure Arc Elevation of Privilege Vulnerability
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Severity
10.0 Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-706Use of Incorrectly-Resolved Name or Reference
Timeline
Published20 Aug 2026
Updated3 Sep 2026
First seen20 Aug 2026
Sources
CVE-2026-65816 · MITRE
Monitor software like this
Free during beta