CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-84782: azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 (exact versions not specified); +19 more affected products

CVE-2026-84782 affects azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0. CVSS 3.1 base score 8.2 (Microsoft Security Response Center). EPSS 0.0039 (percentile 0.30838), scored 2026-10-05. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0. Fixed version: 3.5.9-r0.

Affected technology

azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft

azl3 edk2 20240524git3e722403cd16-20 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft

azl3 kata-containers 4.1.0.kata0-1 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft

azl3 openssl 3.3.7-6 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft

azl3 openvmm 0.1.0-1 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft

azl3 qemu 10.1.0-1 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft

azl3 rust 1.75.0-31 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft

azl3 rust 1.96.1-2 on Azure Linux 3.0 · Exact affected versions not specified by the source
Microsoft

libcrypto3 · Exact affected versions not specified by the source
Vendor not specified by the source

libssl3 · Exact affected versions not specified by the source
Vendor not specified by the source

openssl · Exact affected versions not specified by the source
Vendor not specified by the source

openssl-dbg · Exact affected versions not specified by the source
Vendor not specified by the source

openssl-dev · Exact affected versions not specified by the source
Vendor not specified by the source

openssl-doc · Exact affected versions not specified by the source
Vendor not specified by the source

openssl-engine-afalg · Exact affected versions not specified by the source
Vendor not specified by the source

openssl-engine-capi · Exact affected versions not specified by the source
Vendor not specified by the source

openssl-engine-loader-attic · Exact affected versions not specified by the source
Vendor not specified by the source

openssl-engine-padlock · Exact affected versions not specified by the source
Vendor not specified by the source

openssl-fips-config · Exact affected versions not specified by the source
Vendor not specified by the source

openssl-provider-legacy · Exact affected versions not specified by the source
Vendor not specified by the source

Component: Not specified by the source

Attack conditions (Microsoft Security Response Center, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Microsoft Security Response Center’s CVSS 3.1 assessment rates confidentiality impact as low; integrity impact as none; availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

Product
azl3 cloud-hypervisor 52.0.152-1 on Azure Linux 3.0
CCR priority
32.9 /100 (P4)
CVSS 3.1
8.2 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H · Microsoft Security Response Center
EPSS
0.0039 · percentile 0.30838 · 2026-10-05
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-84782.html