Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

A critical cryptographic integrity flaw in the Azure Linux 3.0 cloud-hypervisor package allows forged CMS AuthEnvelopedData messages to pass authentication checks, carrying a CVSS base score of 9.1. Organizations running Microsoft Azure Linux 3.0 virtual machines on Azure infrastructure with the affected cloud-hypervisor package (azl3 version 51.1.56-1) are at risk of workload isolation compromise and inter-VM communication tampering. Microsoft disclosed this vulnerability as part of the June 2026 Patch Tuesday cycle; patching should be treated as urgent for affected Azure Linux 3.0 deployments.

Author

Tech Jacks Solutions