Microsoft
Microsoft Azure ARC: vulnerabilidades y CVE
Microsoft Azure ARC tiene 7 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses5
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-70009 | Crítica (9.8) | 0.53% | — | 17 sept 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-69399 | Crítica (9.8) | 0.48% | — | 17 sept 2026 | Azure Arc Elevation of Privilege Vulnerability |
| CVE-2026-62895 | Alta (8.8) | 0.82% | — | 8 sept 2026 | Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-69555 | Crítica (10) | 0.80% | — | 20 ago 2026 | Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-24302 | Crítica (9.8) | 1.6% | — | 5 feb 2026 | Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-26627 | Alta (7) | 0.88% | — | 11 mar 2025 | Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally. |
| CVE-2022-38007 | Alta (7.8) | 0.69% | — | 13 sept 2022 | Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability |