VORANT. Threat Intelligence Sign in Get the full feed

Microsoft patches 33 Azure Linux flaws

medium vulnerability

Microsoft released patches for 33 vulnerabilities in Azure Linux 3 components, including kernel, QEMU, and system libraries, enabling privilege escalation.

CERT-FR has issued an advisory covering 33 vulnerabilities affecting Microsoft Azure Linux 3 (azl3) components. The flaws span multiple core packages including the Linux kernel (6.6.139.1-1 and earlier), QEMU (9.1.0-7 and earlier), EDK2 firmware, Erlang runtime, OpenSC smart card library, and Python pip. All vulnerabilities enable privilege escalation, with one categorized as an unspecified security issue by the vendor.

Microsoft published security bulletins between June 4-17, 2026, addressing the vulnerabilities with CVE identifiers ranging from CVE-2026-7383 to CVE-2026-49760. Affected organizations running Azure Linux 3 should apply the vendor-supplied patches immediately. The affected packages include fundamental system components: kernel 6.6.141.1-1, QEMU 9.1.0-8, EDK2 20240524git3e722403cd16-18, Erlang 26.2.5.21-2, OpenSC 0.27.1-2, and Python pip 24.2-9.

While the advisory provides limited technical detail on exploitation vectors or real-world targeting, the scope and privilege-escalation impact warrant prompt remediation by Azure Linux users. Microsoft's security bulletins contain detailed patch information and affected version specifics.

Mentioned in this report

Vulnerabilities CVE-2026-10275CVE-2026-34180CVE-2026-42766CVE-2026-42767CVE-2026-45445CVE-2026-45447CVE-2026-46274CVE-2026-46280CVE-2026-46285CVE-2026-46287CVE-2026-46289CVE-2026-46291CVE-2026-46292CVE-2026-46293CVE-2026-46296CVE-2026-46299CVE-2026-46301CVE-2026-46303CVE-2026-46304CVE-2026-46306CVE-2026-46307CVE-2026-46312CVE-2026-46319CVE-2026-48855CVE-2026-48856CVE-2026-48858CVE-2026-48860CVE-2026-48914CVE-2026-49759CVE-2026-49760CVE-2026-7383CVE-2026-8643CVE-2026-9076

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0783/

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free