CVE-2026-102937 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 python-pip 24.2-10 on Azure Linux 3.0 · azl3 python-virtualenv 20.36.1-6 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-103111 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.1
Update availability Patch status unknown Affected: azl3 php 8.3.33-1 on Azure Linux 3.0 · azl3 python-jwt 2.13.0-1 on Azure Linux 3.0 · +2 more
Updated October 3, 2026
CVE-2026-73064 Microsoft
In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove or inject bytes into the start of the TLS stream. This only affects TLS 1.3 servers.
CVSS 2.9
Update availability Patch status unknown Affected: azl3 qemu 10.1.0-1 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-102559 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.6
Update availability Patch status unknown Affected: azl3 libsoup 3.4.4-16 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-102556 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.6
Update availability Patch status unknown Affected: azl3 libsoup 3.4.4-16 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-102555 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.2
Update availability Patch status unknown Affected: azl3 libsoup 3.4.4-16 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-102558 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.6
Update availability Patch status unknown Affected: azl3 libsoup 3.4.4-16 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-102557 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.6
Update availability Patch status unknown Affected: azl3 libsoup 3.4.4-16 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-102560 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.6
Update availability Patch status unknown Affected: azl3 libsoup 3.4.4-16 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-63209 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Patch status unknown Affected: azl3 keda 2.14.1-19 on Azure Linux 3.0 · azl3 telegraf 1.31.0-33 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-101276 Microsoft
iperf3 3.21 (esnet/iperf) contains a remote, unauthenticated heap use-after-free: the server's per-test watchdog server_timer_proc() frees streams without cancelling/joining their worker threads, so a blocked worker dereferences a freed iperf_stream; fixed in 3.22.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 python-jwt 2.13.0-1 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-72897 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Patch status unknown Affected: azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 · azl3 kata-containers 4.1.0.kata0-1 on Azure Linux 3.0 · +4 more
Updated October 3, 2026
CVE-2026-84784 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Patch status unknown Affected: azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 · azl3 kata-containers 4.1.0.kata0-1 on Azure Linux 3.0 · +4 more
Updated October 3, 2026
CVE-2026-77696 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 3.7
Update availability Patch status unknown Affected: azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 · azl3 kata-containers 4.1.0.kata0-1 on Azure Linux 3.0 · +3 more
Updated October 3, 2026
CVE-2026-35191 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 3.7
Update availability Patch status unknown Affected: azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 · azl3 kata-containers 4.1.0.kata0-1 on Azure Linux 3.0 · +1 more
Updated October 3, 2026
CVE-2026-75804 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 5.3
Update availability Patch status unknown Affected: azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 · azl3 kata-containers 4.1.0.kata0-1 on Azure Linux 3.0 · +3 more
Updated October 3, 2026
CVE-2026-42772 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 5.3
Update availability Patch status unknown Affected: azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 · azl3 kata-containers 4.1.0.kata0-1 on Azure Linux 3.0 · +4 more
Updated October 3, 2026
CVE-2026-54875 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 3.7
Update availability Patch status unknown Affected: azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 · azl3 kata-containers 4.1.0.kata0-1 on Azure Linux 3.0 · +1 more
Updated October 3, 2026
CVE-2026-54872 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 3.7
Update availability Patch status unknown Affected: azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 · azl3 kata-containers 4.1.0.kata0-1 on Azure Linux 3.0 · +3 more
Updated October 3, 2026
CVE-2026-35189 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 5.3
Update availability Patch status unknown Affected: azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 · azl3 kata-containers 4.1.0.kata0-1 on Azure Linux 3.0 · +3 more
Updated October 3, 2026
CVE-2026-84782 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.2
Update availability Patch status unknown Affected: azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 · azl3 edk2 20240524git3e722403cd16-20 on Azure Linux 3.0 · +6 more
Updated October 3, 2026
CVE-2026-75806 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 5.3
Update availability Patch status unknown Affected: azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 · azl3 kata-containers 4.1.0.kata0-1 on Azure Linux 3.0 · +3 more
Updated October 3, 2026
CVE-2026-75805 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 5.3
Update availability Patch status unknown Affected: azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 · azl3 kata-containers 4.1.0.kata0-1 on Azure Linux 3.0 · +2 more
Updated October 3, 2026
CVE-2026-94634 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 thrift 0.24.0-1 on Azure Linux 3.0
Updated October 3, 2026