# Multiple flaws patched in Microsoft Azure Linux

Published: 2026-07-07 · Severity: medium
Canonical: https://vorant.io/reports/47475789-ab36-5b40-8890-2e6dd60d1487/multiple-flaws-patched-in-microsoft-azure-linux

> CERT-FR advises patching several packages in Microsoft Azure Linux affected by multiple unspecified security vulnerabilities.

CERT-FR issued an advisory covering multiple vulnerabilities in Microsoft Azure Linux (azl3), affecting packages including dhcpcd, libssh2, nmap, perl-Bytes-Random-Secure, qemu, runc, tmux, and util-linux. The vendor has not specified the exact nature of the security issues, but nine CVEs are referenced spanning disclosure dates from late June through early July 2026.

No details on exploitation, impact severity, or attack vectors are provided in the advisory. Administrators running affected Azure Linux package versions are advised to consult the Microsoft Security Response Center bulletins and apply the updated package versions referenced in the advisory to remediate the vulnerabilities.

## Mentioned in this report

- Vulnerabilities: CVE-2025-15661, CVE-2026-11623, CVE-2026-11625, CVE-2026-13595, CVE-2026-14258, CVE-2026-3196, CVE-2026-41579, CVE-2026-55199, CVE-2026-58058

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0841

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/47475789-ab36-5b40-8890-2e6dd60d1487/multiple-flaws-patched-in-microsoft-azure-linux.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
