SYS::ONLINE
Wasteland.
Briefs1521
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-58275 2026-07-23

CVE-2026-58275: Critical Missing Authorization Flaw in Azure DNS

"Microsoft disclosed CVE-2026-58275, a maximum-severity (CVSS 10.0) missing-authorization vulnerability in Azure DNS that could let an unauthenticated network attacker elevate privileges."

Microsoft disclosed CVE-2026-58275, a maximum-severity (CVSS 10.0) missing-authorization vulnerability in Azure DNS that could let an unauthenticated network attacker elevate privileges.

What Is It

CVE-2026-58275 is a missing authorization vulnerability (CWE-862) in Microsoft Azure DNS. Per Microsoft's advisory, the flaw "allows an unauthorized attacker to elevate privileges over a network." It carries a CVSS 3.1 base score of 10.0 (CRITICAL), with the vector AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H, network-exploitable, low attack complexity, no privileges or user interaction required, and a changed scope. Impact is rated HIGH for both integrity and availability, with no confidentiality impact.

Why It Matters

A perfect 10.0 score is reserved for the most serious flaws. The combination of no required privileges, no user interaction, and a scope change means an attacker could reach beyond the initially vulnerable component to affect other resources; the hallmark of a privilege-elevation issue that crosses trust boundaries. The HIGH integrity and availability impacts indicate an attacker could tamper with or disrupt affected functionality over the network.

What's Vulnerable

The affected product is Microsoft Azure DNS. Microsoft tags this CVE as an "exclusively-hosted-service," and the NVD record lists the affected version as "-" (all instances of the hosted service). No specific product versions or CPEs are enumerated in the source data.

Patch Status

Because Azure DNS is an exclusively hosted service, remediation is handled on Microsoft's side; the supplied NVD record does not list customer-side patch steps or a required action. As of this writing, the NVD entry carries a status of "Received" and has not yet been fully analyzed. The supplied CISA KEV entry is empty, so there is no confirmation of active exploitation in the source material. Refer to Microsoft's MSRC advisory for authoritative status.

Sources