Microsoft Azure Data Factory Multiple Vulnerabilities (CVE-2026-66800, CVE-2026-62834)

Release Date: 24th August 2026 (Added 1 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations that use Microsoft Azure Data Factory for data integration or ETL pipelines. This alert is intended to be understood by technical users, cloud administrators and systems administrators.

What is it?

CVE-2026-66800 and CVE-2026-62834 are vulnerabilities in Microsoft Azure Data Factory, a cloud-based data integration service. CVE-2026-66800 is a server-side request forgery (SSRF) flaw that allows an unauthorized attacker to disclose information over the network. CVE-2026-62834 is a more severe flaw involving improper verification of a cryptographic signature, allowing an unauthorized attacker to elevate privileges over the network.

Both vulnerabilities can be triggered remotely without authentication or user interaction. Because Azure Data Factory is a Microsoft-managed platform-as-a-service, Microsoft addresses these vulnerabilities on the service side; however, organizations should still confirm through their Azure administration channels whether any tenant-side configuration review or action is expected for their environment.

Reference

  1. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66800
  2. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62834