Microsoft disclosed CVE-2026-58275, a critical missing-authorization flaw in Azure DNS that allowed an unauthenticated attacker to elevate privileges over the network. The vulnerability carries a CVSS 3.1 score of 10.0 with vector AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H and is mapped to CWE-862. Because Azure DNS is a hosted cloud control-plane service, successful exploitation could have enabled unauthorized changes to DNS records, traffic redirection, service disruption, and manipulation of email routing.
Microsoft said the issue was remediated with a service-side fix through the Microsoft Security Update Guide, and no active exploitation had been reported at the time of disclosure. Defenders were urged to review Azure RBAC permissions, audit recent DNS changes, enforce privileged identity protections, and enable logging and alerting for suspicious DNS modifications and role-assignment activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft published CVE-2026-58275 on July 24, 2026 and remediated it with a service-side fix through the Microsoft Security Update Guide. Reporting described the flaw as critical, with potential impacts including unauthorized DNS record changes, traffic redirection, and service disruption.
Microsoft confirmed CVE-2026-58275, a missing authorization vulnerability in Azure DNS that could allow unauthenticated attackers to elevate privileges over the network. The issue was described as affecting the Azure DNS hosted service and requiring no user interaction.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.