// Microsoft AzureCRITICAL
Microsoft disclosed CVE-2026-62835, a critical improper authorization vulnerability in Azure Portal on July 24, 2026, with a CVSS score of 9.3. The flaw allows unauthenticated remote attackers to disclose sensitive information via network access with no privileges or user interaction required. Microsoft has released an official fix; the service is auto-patched for Azure Portal users.
- CVE-2026-62835: CWE-285: Improper Authorization in Microsoft Azu(opens in a new tab)
- Critical Info Disclosure in Azure Portal (CVE-2026-62835) – TheH(opens in a new tab)
// Get alerts for Microsoft Azure