Skip to main content
← CVE Tracker

Vendor

Azure

14 articles

Azure Cosmos DB CosmosEscape Flaw: Cross-Tenant Database Access
HIGH
Cloud Security

Azure Cosmos DB CosmosEscape Flaw: Cross-Tenant Database Access

Wiz researchers uncover CosmosEscape, a sandbox escape in Azure Cosmos DB's Gremlin API allowing unauthorized cross-tenant read and write access.

Runtime Rebel Intel
4 min read · Jul 30, 2026
Confused Deputy Flaws in Google Cloud & Azure: Admin Bypass
HIGH
Cloud Security

Confused Deputy Flaws in Google Cloud & Azure: Admin Bypass

Analysis of 'Confused Deputy' vulnerabilities across Google Cloud and Microsoft Azure, enabling administrative privilege escalation and access control bypass.

Runtime Rebel Intel
5 min read · Jul 28, 2026
Azure Automation Default Setting: Cross-Tenant Identity Takeover
HIGH
Cloud Security

Azure Automation Default Setting: Cross-Tenant Identity Takeover

Runtime Rebel analyzes a critical security flaw in Azure Automation's default settings allowing cross-tenant identity takeover and access to sensitive data.

Runtime Rebel Intel
4 min read · Jul 24, 2026
CL
MEDIUM
Cloud Security

Microsoft 365 Outage: How an Automated Network Maintenance Bug Impacted Azure

Technical analysis of the Microsoft 365 and Azure outage caused by a bug in the automated network maintenance system, resulting in accidental IP route removal.

Runtime Rebel Intel
4 min read · Jul 24, 2026
ID
MEDIUM
Identity & Access

Azure CLI Password Spray Campaign: Defending 81 Million Login Attempts

A massive password spray campaign targeting Azure CLI via LSHIY hosting infrastructure has been detected, highlighting the urgent need for conditional access.

Runtime Rebel Intel
3 min read · Jul 1, 2026
CL
INFO
Cloud Security

Falcon Cloud Security Expands Multi-Cloud Coverage for Azure, GCP

CrowdStrike Falcon Cloud Security's latest updates enhance multi-cloud protection across Azure and Google Cloud, improving visibility and threat detection.

Runtime Rebel Intel
4 min read · Jun 30, 2026
CL
MEDIUM
Cloud Security

Azure Backup for AKS Vulnerability: Risks of Silent Patches

A reported Azure Backup for AKS vulnerability allowed potential cluster compromise. Learn why Microsoft rejected the report and the impact of silent fixes.

Runtime Rebel Intel
3 min read · May 17, 2026
VU
HIGH
Vulnerabilities

Microsoft's 137 Patches: Critical Flaws in Azure, Windows, Dynamics

Microsoft's latest security updates address 137 vulnerabilities, including critical flaws in Azure, Windows, and Dynamics 365, requiring immediate patching.

Runtime Rebel Intel
4 min read · May 12, 2026
CL
HIGH
Cloud Security

ConsentFix v3: How Attackers Automate Azure OAuth Abuse

Attackers use ConsentFix v3 to automate illicit consent grants in Microsoft Azure, enabling persistent access to Entra ID data without user passwords.

Runtime Rebel Intel
4 min read · May 2, 2026
VU
HIGH
Vulnerabilities

CVE-2025-14510: ABB Ability OPTIMAX Azure AD SSO Auth Bypass

CISA warns of CVE-2025-14510 impacting ABB Ability OPTIMAX, allowing authentication bypass on Azure AD SSO integrations. Patch immediately.

Runtime Rebel Intel
4 min read · May 1, 2026
VU
HIGH
Vulnerabilities

Microsoft Awards $2.3M for Cloud and AI Vulnerabilities at Zero Day Quest

Microsoft pays $2.3 million for nearly 700 vulnerability submissions targeting Azure, Microsoft 365, and AI services during the Zero Day Quest event.

Runtime Rebel Intel
4 min read · Apr 15, 2026
APT41 Deploys Stealth Backdoor for Cloud Credential Harvesting
HIGH
Threat Intel

APT41 Deploys Stealth Backdoor for Cloud Credential Harvesting

China-linked APT41 is targeting AWS, Azure, and Google Cloud with a new zero-detection backdoor designed to harvest credentials and maintain persistence.

Runtime Rebel Intel
4 min read · Apr 13, 2026
TH
MEDIUM
Threat Intel

Azure Monitor Alert Abuse: Detecting Callback Phishing Campaigns

Threat actors are abusing Microsoft Azure Monitor Action Groups to send legitimate-looking callback phishing emails to bypass traditional security filters.

Runtime Rebel Intel
4 min read · Mar 21, 2026
Native Launches Multicloud Security Control Plane for Policy Enforcement
INFO
Cloud Security

Native Launches Multicloud Security Control Plane for Policy Enforcement

Native introduces a security control plane that translates and enforces consistent policies across AWS, Azure, GCP, and Oracle using provider-native APIs.

Runtime Rebel Intel
4 min read · Mar 20, 2026