CVE-2026-62895: Microsoft Azure Arc SQL Server Extension
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Affected products
- Microsoft Azure Arc SQL Server Extension: from 1.0.0.0, before 1.1.3518.465 (fixed in 1.1.3518.465)
Published 2026-09-08. Last modified 2026-09-10.