Get real-time updates on Telegram
CVE-2026-75804: azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 (exact versions not specified); +16 more affected products
CVE-2026-75804 affects azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0. CVSS 3.1 base score 5.3 (Microsoft Security Response Center). EPSS 0.00352 (percentile 0.26555), scored 2026-10-05. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0.
Affected technology
azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft
azl3 kata-containers 4.1.0.kata0-1 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft
azl3 openssl 3.3.7-6 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft
azl3 openvmm 0.1.0-1 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft
azl3 rust 1.96.1-2 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft
libcrypto3 · Exact affected versions not specified by the source
Vendor not specified by the source
libssl3 · Exact affected versions not specified by the source
Vendor not specified by the source
openssl · Exact affected versions not specified by the source
Vendor not specified by the source
openssl-dbg · Exact affected versions not specified by the source
Vendor not specified by the source
openssl-dev · Exact affected versions not specified by the source
Vendor not specified by the source
openssl-doc · Exact affected versions not specified by the source
Vendor not specified by the source
openssl-engine-afalg · Exact affected versions not specified by the source
Vendor not specified by the source
openssl-engine-capi · Exact affected versions not specified by the source
Vendor not specified by the source
openssl-engine-loader-attic · Exact affected versions not specified by the source
Vendor not specified by the source
openssl-engine-padlock · Exact affected versions not specified by the source
Vendor not specified by the source
openssl-fips-config · Exact affected versions not specified by the source
Vendor not specified by the source
openssl-provider-legacy · Exact affected versions not specified by the source
Vendor not specified by the source
Component: Not specified by the source
Attack conditions (Microsoft Security Response Center, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
Microsoft Security Response Center’s CVSS 3.1 assessment rates confidentiality and integrity impact as none; availability impact as low. The description does not specify what an attacker can achieve beyond these rated impacts.
- Product
- azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0
- CCR priority
- 21.3 /100 (P4)
- CVSS 3.1
- 5.3 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L · Microsoft Security Response Center
- EPSS
- 0.00352 · percentile 0.26555 · 2026-10-05
- KEV
- no
Provenance
- Microsoft MSRC Security Update Guide (CVRF) · Source record · observed 2026-10-04 07:08:49.022374+00:00 UTC
- OSV.dev · Source record · observed 2026-10-06 17:58:42.508367+00:00 UTC
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-06 09:23:48.197899+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-75804.html