DIRAS TAKE
Urgent: this is a remote, pre-auth vulnerability with maximum severity (CVSS 10.0) so prioritize mitigation now; immediately limit registry exposure and prepare to apply vendor fixes when they are released.
What is CVE-2026-69865?
An attacker can bypass authorization in Microsoft Azure Container Registry and gain privileged access to registry resources, potentially allowing full read and write control; this issue is tracked as CVE-2026-69865. The vulnerability affects Azure Container Registry (affected versions/details unspecified in the advisory). According to published metrics the flaw requires only network access and no prior authentication or user interaction to exploit, enabling remote abuse from network-exposed environments. The weakness is classified as CWE-639 (Authorization Bypass Through User-Controlled Key).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Which versions of Microsoft Azure Container Registry are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Azure Container Registry | - |
Is CVE-2026-69865 being exploited?
There are no public reports of active exploitation as of 2026-09-29.
How to fix CVE-2026-69865
- Follow Microsoft guidance and apply vendor updates as soon as fixed builds are released for Azure Container Registry.
- Restrict public access to registries and limit network exposure using firewalls and private endpoints.
- Rotate keys and credentials associated with affected registries and remove any untrusted user-controlled keys.
- Monitor registry access logs and alert on anomalous pushes, pulls, or permission changes.
Frequently asked questions
Is CVE-2026-69865 being actively exploited?
There are no public reports of exploitation of CVE-2026-69865 as of 2026-09-29.
Which Azure Container Registry versions are affected by CVE-2026-69865?
The advisory identifies Azure Container Registry as affected but does not list specific version or build numbers.
Is there a patch for CVE-2026-69865?
A patch is reported as available in the advisory metadata, but no fixed version identifiers were provided; apply Microsoft updates as they publish fixed releases.
Does CVE-2026-69865 require authentication?
No — the vulnerability can be exploited without prior authentication according to the published vulnerability metrics.
References
- nvd.nist.gov/vuln/detail/CVE-2026-69865
- cve.org/CVERecord?id=CVE-2026-69865
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69865
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026