Cloud and sovereign cloud

Microsoft Azure advisories: every record the registers tie to its products

In one line

29 advisories are attributed to Microsoft Azure products in this record, covering August 2025 to July 2026, and none of them appears in the CISA catalogue of known exploited vulnerabilities. A further 33 register entries mention Microsoft Azure without naming one of its products as affected, and are excluded rather than counted. Each entry below links to the register that published it.

Attributed

29

tied to a named product

Known exploited

0

in the CISA catalogue

Rated critical

2

by the register

Last checked

Jul 17, 2026

sources re-queried

Why this list is shorter than a CVE mirror

The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of Microsoft Azure, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.

33 entries did not clear that bar and are not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.

29 of the 29 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.

The full list, most recently exploited and most recent first

Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.

  • WID-SEC-2026-2321highCVSS 8.8Jul 16, 2026

    Affected products: Microsoft Azure

  • WID-SEC-2026-2184highCVSS 9.9Jul 03, 2026

    Affected products: Microsoft Azure, Microsoft Entra

  • WID-SEC-2026-2017highCVSS 10.0Jun 22, 2026

    Affected products: Microsoft Azure

  • WID-SEC-2026-1842highCVSS 10.0Jun 10, 2026

    Affected products: Microsoft Azure, Microsoft Azure Stack

  • WID-SEC-2026-1649highCVSS 10.0May 26, 2026

    Affected products: Microsoft Azure, Microsoft Azure Stack

  • WID-SEC-2026-1577highCVSS 10.0May 19, 2026

    Affected products: Microsoft Azure

  • WID-SEC-2026-1486highCVSS 9.9May 13, 2026

    Affected products: Microsoft Azure, Microsoft Windows Admin Center

  • WID-SEC-2026-1419highCVSS 9.9May 13, 2026

    Affected products: Microsoft Azure

  • WID-SEC-2025-2563highCVSS 8.8May 12, 2026

    Affected products: Fedora Linux, SUSE Linux, Microsoft Azure Linux, Microsoft Windows

  • WID-SEC-2026-1414highCVSS 10.0May 08, 2026

    Affected products: Microsoft Azure

  • WID-SEC-2026-0080mediumCVSS 7.8Apr 16, 2026

    Affected products: Microsoft Windows Admin Center, SUSE Linux, SUSE openSUSE, Microsoft Azure

  • WID-SEC-2026-1098highCVSS 8.8Apr 15, 2026

    Affected products: Microsoft Azure

  • WID-SEC-2026-0963highCVSS 10.0Apr 07, 2026

    Affected products: Microsoft Azure

  • WID-SEC-2026-0794highCVSS 10.0Mar 20, 2026

    Affected products: Microsoft Azure

  • WID-SEC-2026-0655highCVSS 8.8Mar 11, 2026

    Affected products: Microsoft Azure, Microsoft Azure Linux, Microsoft Windows, Microsoft Windows Admin Center

  • WID-SEC-2026-0616mediumCVSS 6.7Mar 06, 2026

    Affected products: Microsoft Azure

  • WID-SEC-2025-0544highCVSS 8.4Feb 19, 2026

    Affected products: SUSE Linux, SUSE openSUSE, Microsoft Azure, Microsoft Azure CLI

  • WID-SEC-2026-0370highCVSS 9.8Feb 11, 2026

    Affected products: Microsoft Azure, Microsoft Azure DevOps Server

  • WID-SEC-2026-0329highCVSS 9.8Feb 09, 2026

    Affected products: Microsoft Azure

  • WID-SEC-2026-0201highCVSS 9.9Jan 26, 2026

    Affected products: Microsoft Azure, Microsoft 365 Copilot, Microsoft Entra

  • WID-SEC-2025-2890highCVSS 10.0Dec 19, 2025

    Affected products: Microsoft Azure Cosmos DB, Microsoft Azure

  • WID-SEC-2025-2779highCVSS 8.8Dec 10, 2025

    Affected products: Microsoft Azure

  • WID-SEC-2025-2688highCVSS 9.8Nov 27, 2025

    Affected products: Microsoft Azure, Microsoft SharePoint, Microsoft Defender, Microsoft Dynamics 365

  • WID-SEC-2025-2558mediumCVSS 7.3Nov 12, 2025

    Affected products: Microsoft Azure

  • WID-SEC-2025-2276highCVSS 8.2Oct 15, 2025

    Affected products: Microsoft Azure

  • WID-SEC-2025-2004criticalCVSS 9.8Sep 12, 2025

    Affected products: Microsoft Entra, Microsoft Azure

  • WID-SEC-2025-1971criticalCVSS 10.0Sep 10, 2025

    Affected products: Microsoft Entra, Microsoft Azure

  • WID-SEC-2025-1780highCVSS 10.0Aug 13, 2025

    Affected products: Microsoft Azure Stack, Microsoft Azure

  • WID-SEC-2025-1745highCVSS 10.0Aug 11, 2025

    Affected products: Microsoft Azure

Which registers contributed

RegisterOperated byEntriesLatest
European Vulnerability DatabaseENISA, European Union31Jul 16, 2026
CERT-Bund security advisoriesBSI, Federal Republic of Germany30Jul 16, 2026
Known Exploited Vulnerabilities catalogueCISA, United States1Jun 02, 2023

The entry counts here are the raw register totals for Microsoft Azure, before attribution. They are larger than the list above for exactly that reason.

Questions this page answers

How many vulnerabilities does Microsoft Azure have?

29 advisories in this record are tied by a register to a product of Microsoft Azure. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.

Are any Microsoft Azure vulnerabilities being actively exploited?

None of the 29 records here appears in the CISA catalogue of known exploited vulnerabilities. That catalogue is not exhaustive: it lists what CISA has confirmed as exploited, so absence from it is not proof that nothing has been exploited.

Why does this page show fewer CVEs for Microsoft Azure than other sites?

Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 33 register entries name Microsoft Azure without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.

Where do the Microsoft Azure advisories on this page come from?

From European Vulnerability Database (ENISA, European Union); CERT-Bund security advisories (BSI, Federal Republic of Germany); Known Exploited Vulnerabilities catalogue (CISA, United States). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.

Does a long advisory list mean Microsoft Azure is insecure?

No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.

A list of advisories is not a risk assessment

What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.

The full Microsoft Azure record, including sources and open questions

Microsoft Azure vulnerabilities: all 29 advisories on record, with sources | DecisionOS by nexalign