Junglewise Threat Intelligence

CVE-2026-40411: Microsoft Azure Virtual Network Gateway remote code execution

CVE-2026-40411 · Severity: critical · CVSS 9.9 · Published 2026-05-22

Vendors: Microsoft.

Executive brief

Microsoft Azure Virtual Network Gateway, a service used to connect on-premises networks to Azure via VPN, contains a critical vulnerability. An attacker with basic user permissions can execute malicious code across the network, potentially leading to a full takeover of the gateway service. This could result in unauthorized access to private corporate data, interception of network traffic, or a complete disruption of connectivity between office locations and the cloud.

Technical details

A remote code execution vulnerability exists in the Microsoft Azure Virtual Network Gateway due to improper input validation (CWE-20). An attacker authenticated with low-privileged user permissions can exploit this flaw by sending specially crafted network requests to the gateway. Successful exploitation allows for arbitrary code execution with high privileges. Because the vulnerability carries a 'Scope: Changed' (S:C) designation in its CVSS vector, an attacker may be able to impact components beyond the immediate security scope of the gateway itself. Microsoft has addressed this in their cloud service; users of exclusively hosted services typically receive these updates automatically.

Affected products

  • Microsoft Azure Virtual Network Gateway

Timeline

  • 2026-05-22: disclosed
  • 2026-05-22: advisory: MSRC advisory published

References