
CISA Adds Microsoft Azure Active Directory Flaw to Exploited Vulnerabilities List
CISA added CVE-2026-45480, a Microsoft Azure Active Directory flaw, to its exploited vulnerabilities catalog.
CISA has added a Microsoft Azure Active Directory vulnerability to its Known Exploited Vulnerabilities catalog, signaling that federal civilian agencies and private-sector defenders should treat the issue as an active risk rather than a routine patch-management item.
The July 29 alert says the agency added one vulnerability to the KEV catalog based on evidence of active exploitation. The entry tracks CVE-2026-45480, an improper authentication flaw in Azure Active Directory that Microsoft and the CVE record describe as allowing an unauthorized attacker to elevate privileges over a network. NIST's National Vulnerability Database lists the issue with a CVSS 3.1 score of 10.0 and tags it as an exclusively hosted service vulnerability.
Why identity teams should care
Cloud identity systems sit near the center of many enterprise security programs. A privilege-escalation flaw in that layer can matter far beyond one application because identity providers control access to email, cloud consoles, collaboration tools, developer systems and administrative workflows. CISA's KEV listing does not publish operational exploit details, but the catalog is specifically reserved for vulnerabilities the agency says are being exploited in the wild.
For federal civilian executive branch agencies, a KEV addition creates a binding remediation requirement under CISA's vulnerability management directive. For other organizations, the catalog is widely used as a prioritization signal because it narrows the focus from theoretical severity to vulnerabilities with observed attacker activity.
What defenders can do now
- Confirm whether Microsoft has already remediated the hosted-service issue for the tenant and review any related Microsoft Security Response Center guidance.
- Audit privileged account activity, recent role changes and authentication anomalies around the period when exploitation was reported.
- Review conditional access, break-glass accounts, application permissions and high-privilege service principals for unusual changes.
- Use the KEV listing to escalate internal tracking even if normal CVSS-based workflows had already recorded the vulnerability.
The practical takeaway is prioritization. CVE-2026-45480 was disclosed in June, but CISA's July 29 KEV action adds a new signal: defenders should verify remediation and look for suspicious identity-plane activity now, especially in environments where Azure Active Directory remains a critical access-control layer.
Sources
Cover photo by Jakub Zerdzicki on Pexels, used under the Pexels License.
CyberOGZ Team






Comments (0)
Leave a Comment