VORANT. Threat Intelligence Sign in Get the full feed

Microsoft Azure Linux patches dozens of CVEs

medium vulnerability

CERT-FR advisory details ~40 vulnerabilities across multiple Azure Linux (azl3) packages including OpenSSH, ClamAV, Node.js, and Vim, with no vendor-specified severity or known exploitation.

CERT-FR has published an advisory summarizing a large batch of vulnerabilities affecting Microsoft Azure Linux (azl3) distribution packages, including clamav, curl, erlang, glib, keras, libXfont2, mtr, nodejs, openssh, perl-DBI, python-msgpack, python-setuptools, telegraf, vim, and xorg-x11-server-Xwayland. Each affected package has a specific version threshold below which systems are considered vulnerable, with fixed versions available from Microsoft.

The advisory does not specify the exact nature of the security impact for each CVE, stating only that a successful attacker could trigger an unspecified security issue. Roughly 40 CVEs are referenced across the affected components, spanning issue disclosure dates from late June through mid-July 2026. This is a standard vendor patch bulletin aggregation rather than a report of active exploitation, targeted campaign, or novel technique.

Organizations running Microsoft Azure Linux 3.0 (azl3) should prioritize patching per the referenced Microsoft Security Response Center bulletins for each CVE. No indicators of compromise, threat actor attribution, or malware association are present in this disclosure; the advisory is purely a consolidated notification of upstream package updates.

Mentioned in this report

Vulnerabilities CVE-2026-10536CVE-2026-11525CVE-2026-12064CVE-2026-12480CVE-2026-14380CVE-2026-14461CVE-2026-14739CVE-2026-14740CVE-2026-20213CVE-2026-20214CVE-2026-20215CVE-2026-20216CVE-2026-20217CVE-2026-54886CVE-2026-54908CVE-2026-56000CVE-2026-56001CVE-2026-56002CVE-2026-56003CVE-2026-57585CVE-2026-58010CVE-2026-58011CVE-2026-58012CVE-2026-58013CVE-2026-58014CVE-2026-58015CVE-2026-58016CVE-2026-59995CVE-2026-59996CVE-2026-59997CVE-2026-59999CVE-2026-60000CVE-2026-60001CVE-2026-60002CVE-2026-8286CVE-2026-8458CVE-2026-8926CVE-2026-8927CVE-2026-8932CVE-2026-9079

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0873

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free