Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-65816: Azure Arc lets attackers gain higher permissions
CVE-2026-65816 · published 14 days ago
Summary
Azure Arc, the tool that links on‑premise resources to Azure, has a flaw that could let an outsider raise their access level across the network. This could expose sensitive data or allow changes to systems. Install Microsoft’s latest security update and review your Azure Arc permissions right away.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | azure web apps | - |
| microsoft | azure_web_apps |
All versions
cpe:2.3:a:microsoft:azure_web_apps:-:*:*:*:*:*:*:* |
Original advisory text
Azure Arc Elevation of Privilege Vulnerability
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65816 vendor-advisory patch
Severity
10.0
Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-706Use of Incorrectly-Resolved Name or Reference
Timeline
Published20 Aug 2026
Updated3 Sep 2026
First seen20 Aug 2026
Monitor software like this
Free during beta