CVE-2026-19553 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 python3 3.12.14-2 on Azure Linux 3.0 · azl3 tensorflow 2.16.1-11 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-102925 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.8
Update availability Patch status unknown Affected: azl3 python-virtualenv 20.36.1-6 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-102930 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 python-virtualenv 20.36.1-6 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-97689 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 python-jwt 2.13.0-1 on Azure Linux 3.0 · azl3 tensorflow 2.16.1-11 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-97687 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 python-jwt 2.13.0-1 on Azure Linux 3.0 · azl3 python-pip 24.2-10 on Azure Linux 3.0 · +3 more
Updated October 3, 2026
CVE-2026-102937 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 python-pip 24.2-10 on Azure Linux 3.0 · azl3 python-virtualenv 20.36.1-6 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-103111 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.1
Update availability Patch status unknown Affected: azl3 php 8.3.33-1 on Azure Linux 3.0 · azl3 python-jwt 2.13.0-1 on Azure Linux 3.0 · +2 more
Updated October 3, 2026
CVE-2026-102559 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.6
Update availability Patch status unknown Affected: azl3 libsoup 3.4.4-16 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-102556 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.6
Update availability Patch status unknown Affected: azl3 libsoup 3.4.4-16 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-102555 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.2
Update availability Patch status unknown Affected: azl3 libsoup 3.4.4-16 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-102558 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.6
Update availability Patch status unknown Affected: azl3 libsoup 3.4.4-16 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-102557 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.6
Update availability Patch status unknown Affected: azl3 libsoup 3.4.4-16 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-102560 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.6
Update availability Patch status unknown Affected: azl3 libsoup 3.4.4-16 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-63209 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Patch status unknown Affected: azl3 keda 2.14.1-19 on Azure Linux 3.0 · azl3 telegraf 1.31.0-33 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-72897 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Patch status unknown Affected: azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 · azl3 kata-containers 4.1.0.kata0-1 on Azure Linux 3.0 · +4 more
Updated October 3, 2026
CVE-2026-84784 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 7.5
Update availability Patch status unknown Affected: azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 · azl3 kata-containers 4.1.0.kata0-1 on Azure Linux 3.0 · +4 more
Updated October 3, 2026
CVE-2026-84782 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.2
Update availability Patch status unknown Affected: azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 · azl3 edk2 20240524git3e722403cd16-20 on Azure Linux 3.0 · +6 more
Updated October 3, 2026
CVE-2026-91135 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 thrift 0.24.0-1 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-96294 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 thrift 0.24.0-1 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-94646 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 thrift 0.24.0-1 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-94645 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 thrift 0.24.0-1 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-86535 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS Not supplied
Update availability Patch status unknown Affected: azl3 thrift 0.24.0-1 on Azure Linux 3.0
Updated October 3, 2026
CVE-2026-96940 Microsoft
An elevation of privilege vulnerability exists when Microsoft Exchange Outlook Web Access (OWA) fails to properly handle web requests. An attacker who successfully exploited this vulnerability could perform script/content injection attacks and attempt to trick the user into disclosing sensitive information. To exploit the vulnerability, an attacker could send a specially crafted email message containing a malicious link to a user. Alternatively, an attacker could use a chat client to social engineer a user into clicking the malicious link. The security update addresses the vulnerability by correcting how Microsoft Exchange validates web requests. Note: In order to exploit this vulnerability, a user must click a maliciously crafted link from an attacker.
CVSS 8.8
Update availability Security update available Affected: Microsoft Exchange Server 2016 Cumulative Update 23 · Microsoft Exchange Server 2019 Cumulative Update 14 · +2 more
Updated October 2, 2026
CVE-2026-74556 Microsoft
Review the authoritative advisory for the vulnerability description and applicability.
CVSS 8.8
Update availability Patch status unknown Affected: azl3 kernel 6.6.150.1-1 on Azure Linux 3.0
Updated October 2, 2026