Security update: Redis response to the Kimi K3 vulnerability claims

ZTS 65 Reputation points
2026-07-30T13:00:48.4666667+00:00

We reviewed the following Redis security advisory:

https://redis.io/blog/security-update-redis-response-to-the-kimi-k3-vulnerability-claims/

Could you please confirm whether a patch or security update is available for this reported vulnerability? If not, is there an estimated timeline for when a patch will be released?

Azure Cache for Redis
Azure Cache for Redis

An Azure service that provides access to a secure, dedicated Redis cache, managed by Microsoft.

0 comments No comments

2 answers

Sort by: Most helpful
  1. Sina Salam 31,056 Reputation points Volunteer Moderator
    2026-07-30T17:10:57.3633333+00:00

    Hello ZTS,

    Welcome to the Microsoft Q&A and thank you for posting your questions here.

    I understand that you are asking whether Microsoft has released, or will release, a security update for Azure Cache for Redis / Azure Managed Redis in response to the Redis “Kimi K3” vulnerability claims.

    Azure Cache for Redis and Azure Managed Redis are managed services, so customers cannot manually install Redis server or RedisBloom patches on the service nodes. - https://docs.azure.cn/en-us/azure-cache-for-redis/cache-tls-configuration, https://learn.microsoft.com/en-us/azure/azure-cache-for-redis/cache-azure-active-directory-for-authentication

    Redis publicly confirmed that the reported issues involved Redis Streams and RedisBloom components, and Redis released security updates for affected open-source Redis and RedisBloom versions. - https://azure.microsoft.com/en-us/products/cache/, https://learn.microsoft.com/en-us/azure/azure-cache-for-redis/cache-best-practices-enterprise-tiers

    The only way to confirm whether a specific Azure Redis instance is affected, already remediated, or awaiting remediation is to raise an Azure Support request via your Azure Portal with the cache resource ID, subscription ID, region, SKU, Redis version, and module configuration.

    I hope this is helpful. Please! Do not hesitate to let me know if you have any other questions, steps or clarifications.


    Please do not close the thread by upvoting and accepting the answer if any part of it is helpful.

    Was this answer helpful?

    0 comments No comments

  2. Divyesh Govaerdhanan 11,725 Reputation points MVP Volunteer Moderator
    2026-07-30T16:25:08.2366667+00:00

    Hello ZTS,

    Welcome to Microsoft Q&A,

    Thanks for flagging this. Here is how it applies to Azure Cache for Redis.

    The advisory covers three authenticated issues: a Streams shared-NACK use-after-free and two RedisBloom bugs (TDigest out-of-bounds write, TopK wild-free). Redis has already shipped open source fixes in 8.8.1, six older branches, and RedisBloom releases.

    Is a patch available? Yes, and Microsoft handles it. Azure Cache for Redis is a fully managed service, so security patches are applied automatically during platform maintenance. You cannot and do not need to patch the instance yourself. Per the Redis advisory, the fixes are already live in Redis Software and Redis Cloud (which back the Enterprise tiers and Azure Managed Redis), and rollout to remaining managed environments is nearing completion.

    Microsoft does not publish per-instance patch dates. Watch Azure Service Health for notifications, and if you need written confirmation for compliance, raise an Azure support request and the product team can confirm the status for your cache.

    Reference: Redis security advisory (CVE-2026-23479, CVE-2026-25243, CVE-2026-25588, CVE-2026-25589, CVE-2026-23631)

    Please Upvote and accept the answer if it helpss!!

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.