Skip to main content

CVE-2026-62895

Azure Arc SQL Server Extension Elevation of Privilege vulnerability

Microsoft

MSRC advisory September 8, 2026

Alert details

Source feed
Microsoft MSRC
CVE ID
CVE-2026-62895
Affected products
Azure Arc SQL Server Extension Elevation of Privilege · Microsoft Azure Arc SQL Server Extension Elevation of Privilege · Microsoft

What happened

<p>Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p>

What it means for your business

Azure Arc SQL Server Extension Elevation of Privilege vulnerability (CVE-2026-62895) was added to Microsoft’s security update guidance. <p>Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.</p> If you need help checking exposure, call (864) 335-9223.

Sources

Related briefs

Microsoft MSRC

CVE-2026-63532

Microsoft Office Remote Code Execution vulnerability

Microsoft Office Remote Code Execution vulnerability (CVE-2026-63532) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-63516

Microsoft SharePoint Server Spoofing vulnerability

Microsoft SharePoint Server Spoofing vulnerability (CVE-2026-63516) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55123

Microsoft PowerPoint Remote Code Execution vulnerability

Microsoft PowerPoint Remote Code Execution vulnerability (CVE-2026-55123) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2026-55039

Microsoft Excel Remote Code Execution vulnerability

Microsoft Excel Remote Code Execution vulnerability (CVE-2026-55039) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. If you need help checking exposure, call (864) 335-9223.

Need help patching?

PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.