Improper Access Control in Azure API Management by Microsoft
CVE-2026-35425
8HIGH
What is CVE-2026-35425?
An unauthorized attacker could exploit a security oversight in Azure API Management, enabling them to execute arbitrary code remotely. This vulnerability stems from improper access control, which poses a significant risk in networked environments. Organizations using Azure API Management should review their security configurations and apply any recommended patches to mitigate potential threats. For further details and updates, refer to Microsoft's official advisory on this issue.
Affected Version(s)
Azure API Management (APIM) -