ctipilot.ch

Microsoft Azure Local Disconnected Operations (ALDO) — CVSS 10.0 unauthenticated network elevation-of-privilege; MSRC Exploitation More Likely

cve · CVE-2026-42822

Coverage timeline
1
first 2026-05-21 → last 2026-05-21
Briefs
1
1 distinct
Sources cited
134
55 hosts
Sections touched
0
Co-occurring entities
2
see Related entities below

Story timeline

  1. 2026-05-21CTI Daily Brief — 2026-05-21

Source distribution

  • attack.mitre.org21 (16%)
  • microsoft.com11 (8%)
  • msrc.microsoft.com10 (7%)
  • bleepingcomputer.com8 (6%)
  • thehackernews.com8 (6%)
  • github.com5 (4%)
  • helpnetsecurity.com4 (3%)
  • security-hub.ncsc.admin.ch4 (3%)
  • other63 (47%)

Related entities

External references

NVD · cve.org · CISA KEV

All cited sources (134)

Items in briefs about Microsoft Azure Local Disconnected Operations (ALDO) — CVSS 10.0 unauthenticated network elevation-of-privilege; MSRC Exploitation More Likely (1)

CVE-2026-42822 — Microsoft Azure Local Disconnected Operations (ALDO): CVSS 10.0 unauthenticated network elevation-of-privilege, "Exploitation More Likely"

From CTI Daily Brief — 2026-05-21 · published 2026-05-21 · view item permalink →

Microsoft assigned CVE-2026-42822 (CVSS 3.1 = 10.0, CWE-287 Improper Authentication, vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) to an authentication-bypass flaw in Azure Local Disconnected Operations (ALDO) — Microsoft's solution for running Azure services in air-gapped or partially-disconnected infrastructure environments — that allows an unauthorised network attacker to elevate privileges over a network with no credentials and no prior foothold (Microsoft MSRC, 2026-05-18). MSRC rates "Exploitation More Likely"; no in-the-wild exploitation observed and no public PoC at advisory release. Cloud-managed Azure customers using Microsoft-operated Resource Manager environments are already protected — only manually-operated air-gapped Azure Local stacks need action. Remediation requires upgrading ALDO to version 2604 or later via the standard ALDO update channel. Defender takeaway: EU public-sector operators running Azure Local for data-sovereignty / federal data-residency compliance (a common pattern in Bundesverwaltung and German Bundesbehörden environments) should treat this as a Patch-Tuesday-class emergency on disconnected infrastructure where update cadence is typically slower than cloud-managed Azure. Restrict the ALDO management plane to admin-only OOB subnets until v2604 is installed.