CVE-2026-47632

Summary

Improper certificate validation in Azure Connected Machine Agent allows an unauthorized attacker to elevate privileges over an adjacent network.

Affected Software

VendorProductVersion RangeStatus
MicrosoftAzure Connected Machine Agent1.0.0 < 1.65affected

Weaknesses

  • CWE-295: CWE-295: Improper Certificate Validation

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References