CVE-2026-21512
Published Feb 10, 2026Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network.
- evidence mentions
- 2
- Buzz score
- 21.0
Vendor/product archive
40 CVEs tagged to microsoft / azure_devops_server — 2 Critical, 12 High, 26 Medium, 0 Low, 0 Unrated.
Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network.
Azure DevOps Server Spoofing Vulnerability
Azure DevOps Server Spoofing Vulnerability
Azure DevOps Server Remote Code Execution Vulnerability
Azure DevOps Server Spoofing Vulnerability
Azure DevOps Server Elevation of Privilege Vulnerability
Azure DevOps Server Remote Code Execution Vulnerability
Azure DevOps Server Remote Code Execution Vulnerability
Azure DevOps Server Spoofing Vulnerability
Azure DevOps Server Spoofing Vulnerability
Azure DevOps Server Spoofing Vulnerability
Azure DevOps Server Remote Code Execution Vulnerability
Azure DevOps Server Cross-Site Scripting Vulnerability
Azure DevOps Server Spoofing Vulnerability
Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability
Azure DevOps Server and Team Foundation Services Spoofing Vulnerability
Azure DevOps Server Spoofing Vulnerability
Azure DevOps Server and Team Foundation Services Spoofing Vulnerability
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerabil…
A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'.
An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Found…
An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Found…
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerabil…
A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation…
A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vuln…