SYS::ONLINE
Wasteland.
Briefs1674
Issues21
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-47643 2026-06-09

Critical Code Execution Flaw in Azure Stack Edge — CVE-2026-47643 (CVSS 9.8)

"Microsoft has disclosed CVE-2026-47643, a critical remote code execution vulnerability in Azure Stack Edge that lets an unauthenticated attacker run code over the network."

Microsoft has disclosed CVE-2026-47643, a critical remote code execution vulnerability in Azure Stack Edge that lets an unauthenticated attacker run code over the network.

What Is It

CVE-2026-47643 is an external control of file name or path weakness (CWE-73) in Azure Stack Edge. According to Microsoft, the flaw "allows an unauthorized attacker to execute code over a network." It carries a CVSS 3.1 base score of 9.8 (Critical), with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Why It Matters

The metrics describe a worst-case profile: the vulnerability is reachable over the network (AV:N) with low attack complexity (AC:L), requires no privileges (PR:N), and needs no user interaction (UI:N). A successful attack delivers high impact across confidentiality, integrity, and availability; meaning an attacker who reaches a vulnerable device can fully compromise it without authentication. Azure Stack Edge units typically operate as edge appliances bridging on-premises environments and Azure, making remote code execution on them a significant pivot point.

What's Vulnerable

The affected product is Microsoft Azure Stack Edge. The supplied NVD record does not enumerate specific affected versions or CPEs, so consult the Microsoft Security Response Center advisory for the precise build and version coverage.

Patch Status

The CVE was published on 2026-06-09 and is currently in "Awaiting Analysis" status at NVD. The supplied source material does not include a CISA KEV entry, so there is no confirmation of active exploitation in the data provided. Microsoft's MSRC update guide is the authoritative reference for patch availability and remediation guidance; administrators should review it and apply the vendor's fix for affected Azure Stack Edge devices.

Sources