Information Disclosure Vulnerability in Azure IoT SDK by Microsoft
CVE-2026-21528

6.5MEDIUM

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
10 February 2026

What is CVE-2026-21528?

A vulnerability within the Azure IoT SDK allows unauthorized attackers to bind to an unrestricted IP address, potentially disclosing sensitive information over the network. This could lead to unauthorized access to data, highlighting the importance of securing network endpoints and ensuring proper configurations are in place.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Azure IoT Explorer 1.0.0 < 0.15.13

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.