CVE-2026-4421: Zero-Day in Major Cloud Providers

Authentication bypass affecting AWS, Azure, GCP — patch available. CVSS 9.8

A critical zero-day vulnerability identified as CVE-2026-4421 has been discovered affecting authentication mechanisms across major cloud providers including AWS, Azure, and Google Cloud Platform.

The vulnerability carries a CVSS score of 9.8 and allows attackers to bypass authentication controls, potentially gaining unauthorized access to cloud resources. Patches are now available from all affected providers.

Organizations are strongly advised to apply patches immediately and review access logs for signs of unauthorized access dating back to June 2026.

Source: Microsoft Security Response Center