Changeflow GovPing Data Privacy & Cybersecurity Microsoft Product Vulnerability CVE-2026-3731
Priority review Notice Added Final

Microsoft Product Vulnerability CVE-2026-3731

Favicon for www.cert.ssi.gouv.fr CERT-FR Security Advisories
Published March 20th, 2026
Detected March 20th, 2026
Email

Summary

CERT-FR has issued an advisory regarding a vulnerability (CVE-2026-3731) discovered in Microsoft products, specifically affecting azl3 libssh versions prior to 0.10.6-6. The advisory directs users to Microsoft's security bulletin for patch information.

What changed

CERT-FR, the French national cybersecurity agency, has published an advisory (CERTFR-2026-AVI-0334) detailing a vulnerability, CVE-2026-3731, affecting specific versions of azl3 libssh (prior to 0.10.6-6) used within Microsoft products. The advisory notes that the vulnerability allows an attacker to cause an unspecified security issue, with the risk level not specified by the publisher. Users are directed to consult Microsoft's security bulletin for remediation.

Organizations utilizing the affected azl3 libssh versions within their Microsoft product environments should immediately consult the provided Microsoft security bulletin and apply the necessary patches. Failure to do so could expose systems to exploitation, leading to unspecified security breaches. While no specific compliance deadline is mentioned, prompt patching is critical for maintaining system integrity and security posture.

What to do next

  1. Consult Microsoft's security bulletin for CVE-2026-3731.
  2. Apply necessary patches to affected azl3 libssh versions (prior to 0.10.6-6).
  3. Review system configurations for potential exploitation.

Source document (simplified)

Premier Ministre S.G.D.S.N

Agence nationale
de la sécurité des
systèmes d'information

Paris, le 20 mars 2026 N° CERTFR-2026-AVI-0334 Affaire suivie par: CERT-FR

Avis du CERT-FR

Objet: Vulnérabilité dans les produits Microsoft

Gestion du document

| Référence | CERTFR-2026-AVI-0334 |
| Titre | Vulnérabilité dans les produits Microsoft |
| Date de la première version | 20 mars 2026 |
| Date de la dernière version | 20 mars 2026 |
| Source(s) | Bulletin de sécurité Microsoft CVE-2026-3731 du 11 mars 2026 |
Une gestion de version détaillée se trouve à la fin de ce document.


Risque

  • Non spécifié par l'éditeur

Systèmes affectés

  • azl3 libssh 0.10.6-5 versions antérieures à 0.10.6-6

Résumé

Une vulnérabilité a été découverte dans les produits Microsoft. Elle permet à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Documentation


Gestion détaillée du document

  1. le 20 mars 2026 Version initiale

Named provisions

Risque Systèmes affectés Résumé Solutions Documentation

Source

Analysis generated by AI. Source diff and links are from the original.

Classification

Agency
CERT-FR
Published
March 20th, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Substantive
Document ID
CERTFR-2026-AVI-0334

Who this affects

Applies to
Technology companies
Industry sector
3341 Computer & Electronics Manufacturing 5112 Software & Technology
Activity scope
Vulnerability Management Software Patching
Geographic scope
France FR

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Vulnerability Management Software Security

Get Data Privacy & Cybersecurity alerts

Weekly digest. AI-summarized, no noise.

Free. Unsubscribe anytime.

Get alerts for this source

We'll email you when CERT-FR Security Advisories publishes new changes.

Free. Unsubscribe anytime.