Skip to main content

Vendor/product archive

microsoft / azure_devops CVEs

Beta · best-effort

4 CVEs tagged to microsoft / azure_devops3 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-42826

Published May 7, 2026

Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-23658

Published Mar 19, 2026

Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-47158

Published Jul 18, 2025

Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-29813

Published May 8, 2025

Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1