Microsoft Security Update -19 May 2026

Microsoft has released a security update to address a critical vulnerability affecting multiple Microsoft Azure products.

The addressed vulnerability could allow the remote unauthorized attacker to elevate privileges over a network.

The addressed vulnerability:

Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability (CVE-2026-42822):

  • CVSS: 10.0
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Privileges

The affected products:

  • Azure Resource Manager.
  • Azure Local.
Vulnerabilities

CVE-2026-42822

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Microsoft MSRC

References