A critical information disclosure vulnerability (CVSS Base Score 9.3) in the Microsoft Azure Portal allows a remote, anonymous attacker to exploit the service and access sensitive information. The article confirms a mitigation is available but does not specify the exact affected version ranges or the fixed version. IT professionals should immediately consult the official Microsoft advisory for patching guidance.
[WID-SEC-2026-2535] Microsoft Azure Portal: Schwachstelle ermöglicht Offenlegung von Informationen CVSS Base Score 9.3 (kritisch) CVSS Temporal Score 8.1 (hoch) Remoteangriff ja Datum 27.07.2026 Stand 28.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Windows Produktbeschreibung Azure ist eine Cloud Computing-Plattform von Microsoft. Produkte 27.07.2026 Microsoft Azure Portal Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Microsoft Azure Portal ausnutzen, um Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben