35 Total CVEs
35 AI Analyzed
0 CISA KEV
14 Critical

Profile

0% ended up actively exploited 0 of 35 added to CISA KEV
40% rated critical (CVSS 9.0+) 14 critical, 21 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

35 CVEs in the last 12 months

Products

  • Portal Windows2
  • DevOps allows2
  • Logic Apps2
  • Entra ID2
  • AI Foundry2
  • Cloud Shell2
  • Machine Learning2
  • SDK allows2

24 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-35 of 35 CVEs
CVE-2026-42834
Analyzed
7.8
Azure Portal Windows

Improper link resolution before file access ('link following') in Azure Portal Windows Admin Center allows an authorized attacker to elevate privilege...

2026-05-21
CVE-2026-42826
Analyzed
10
Azure DevOps allows

An exposure of sensitive information in Azure DevOps allows an unauthenticated attacker to disclose data over a network.

2026-05-08
CVE-2026-42823
Analyzed
9.9
Azure Logic Apps

Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.

2026-05-13
CVE-2026-42822
Analyzed
10
Azure Local Disconnected

Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to perform privilege escalation over the network.

2026-05-19
CVE-2026-42151
Analyzed
7.5
Azure AD remote

Prometheus is an open-source monitoring system and time series database

2026-05-05
CVE-2026-41105
Analyzed
8.1
Azure Notification Service

Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network

2026-05-08
CVE-2026-40379
Analyzed
9.3
Azure Entra ID

Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network.

2026-05-13
CVE-2026-35435
Analyzed
8.6
Azure AI Foundry

Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network

2026-05-08
CVE-2026-35430
Analyzed
8.8
Azure Privileged Identity Management

Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges ove...

2026-05-27
CVE-2026-35428
Analyzed
9.6
Azure Cloud Shell

A command injection vulnerability in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network.

2026-05-08
CVE-2026-33833
Analyzed
8.2
Azure Machine Learning

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized at...

2026-05-13
CVE-2026-33117
Analyzed
9.1
Azure SDK allows

Improper authentication in Azure SDK allows an unauthorized attacker to bypass a security feature over a network.

2026-05-13
CVE-2026-33107
Analyzed
10
Azure Databricks allows

A Server-Side Request Forgery (SSRF) vulnerability in Azure Databricks allows unauthenticated attackers to elevate privileges and access internal netw...

2026-04-03
CVE-2026-32213
Analyzed
10
Azure AI Foundry

Improper authorization in Azure AI Foundry allows unauthenticated network attackers to escalate privileges, potentially compromising AI models and sen...

2026-04-03
CVE-2026-32211
Analyzed
9.1
Azure MCP Server

A missing authentication vulnerability in Azure MCP Server allows unauthenticated attackers to disclose sensitive information over a network.

2026-04-03
CVE-2026-32207
Analyzed
8.8
Azure Machine Learning

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perf...

2026-05-08
CVE-2026-32173
Analyzed
8.6
Azure SRE Agent

Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network

2026-04-03
CVE-2026-32171
Analyzed
8.8
Azure Logic Apps

Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network

2026-04-15
CVE-2026-32169
Analyzed
10
Azure Cloud Shell

A server-side request forgery (SSRF) vulnerability in Azure Cloud Shell allows an unauthenticated attacker to elevate privileges over a network.

2026-03-20
CVE-2026-26148
Analyzed
8.1
Azure Entra ID

External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally

2026-03-11
CVE-2026-26141
Analyzed
7.8
Azure Arc allows

Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally

2026-03-11
CVE-2026-26135
Analyzed
9.6
Azure Custom Locations

A Server-Side Request Forgery (SSRF) in the Azure Custom Locations Resource Provider allows authenticated attackers to elevate privileges over a netwo...

2026-04-03
CVE-2026-26118
Analyzed
8.8
Azure MCP Server

Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network

2026-03-11
CVE-2026-26117
Analyzed
7.8
Azure Windows Virtual

Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges lo...

2026-03-11
CVE-2026-24302
Analyzed
8.6
Azure Arc Elevation

Azure Arc Elevation of Privilege Vulnerability

2026-02-06
CVE-2026-24300
Analyzed
9.8
Azure Front Door

A critical elevation of privilege vulnerability in Azure Front Door allows attackers to gain unauthorized access levels. Successful exploitation could...

2026-02-06
CVE-2026-23660
Analyzed
7.8
Azure Portal Windows

Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally

2026-03-11
CVE-2026-23659
Analyzed
8.6
Azure Data Factory

Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a networ...

2026-03-20
CVE-2026-23658
Analyzed
8.6
Azure DevOps allows

Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network

2026-03-20
CVE-2026-21532
Analyzed
8.2
Azure Function Information

Azure Function Information Disclosure Vulnerability

2026-02-06
CVE-2026-21531
Analyzed
9.8
Azure SDK allows

A deserialization vulnerability in the Azure SDK allows an unauthenticated attacker to execute arbitrary code over a network by sending specially craf...

2026-02-11
CVE-2026-21515
Analyzed
9.9
Azure IOT Central

Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network.

2026-04-25
CVE-2026-21228
Analyzed
8.1
Azure Local allows

Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network

2026-02-11
CVE-2025-62207
Analyzed
8.6
Azure Multiple Products

Azure Monitor Elevation of Privilege Vulnerability

2025-11-20
CVE-2025-59247
Analyzed
8.8
Azure Multiple Products

Azure PlayFab Elevation of Privilege Vulnerability

2025-10-09