DIRAS TAKE
Treat this as urgent: the flaw requires no authentication and has a critical CVSS 9.8 rating, so immediately limit network exposure and prioritize vendor remediation guidance.
What is CVE-2026-70009?
Remote attackers can use a path traversal flaw to elevate privileges against Azure ARC. CVE-2026-70009 is a path traversal vulnerability (CWE-22) that allows an unauthenticated network attacker to access or overwrite restricted files and gain elevated control of the affected Azure ARC installation; it requires network access and no user interaction. Microsoft identifies Azure ARC as affected, but vendor fixed-version details are not listed in the supplied facts. The weakness is classified as CWE-22 (Path Traversal).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Azure ARC are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Azure ARC | - |
Is CVE-2026-70009 being exploited?
There are no public reports of exploitation as of 2026-09-29; CISA has not added this issue to the Known Exploited Vulnerabilities catalog and no public exploit code is available.
How to fix CVE-2026-70009
- Apply Microsoft’s updates or guidance for Azure ARC as soon as vendor patches are confirmed available.
- Restrict network exposure of Azure ARC endpoints to trusted management networks and block unneeded inbound access.
- Monitor Azure ARC logs and file integrity for unexpected file access or modifications that may indicate path traversal activity.
- Implement additional compensating controls such as host-based file protections and least-privilege service accounts.
Frequently asked questions
Is CVE-2026-70009 being actively exploited?
There are no public reports of exploitation as of 2026-09-29; CISA has not listed it in the Known Exploited Vulnerabilities catalog and no public exploit code is available.
Which Azure ARC versions are affected by CVE-2026-70009?
The supplied information identifies Azure ARC as affected but does not list specific version numbers or fixed releases.
Is there a patch for CVE-2026-70009?
Vendor guidance indicates a patch is available; the supplied facts do not include the fixed-version identifiers, so follow Microsoft’s official update instructions for Azure ARC.
Does CVE-2026-70009 require authentication?
No; the vulnerability allows unauthenticated network attackers to exploit a path traversal condition against Azure ARC without user interaction.
References
- nvd.nist.gov/vuln/detail/CVE-2026-70009
- cve.org/CVERecord?id=CVE-2026-70009
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70009
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026