CVE-2024-49035Active Exploitation(microsoft / partner_center)

LOWCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for microsoft partner_center systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An improper access control vulnerability in Partner.Microsoft.com allows an a unauthenticated attacker to elevate privileges over a network.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-03-18. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • partner_center

Threat summary

  • Active exploitation appears in 2 classified signals
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
partner_center

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-26: 2Active Exploitation · 2026-02-26: 202-26
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • mysocAi@MysocAi
    Active Exploitation

    [HIGH] CISA Adds Microsoft and Zimbra Flaws to KEV Catalog Amid Active Exploitation CISA added CVE-2024-49035 to KEV Catalog due to active exploitation. CVE: CVE-2024-49035 • APT: N/A • Status:… https://xage.com/blog/cyber-attack-news-risk-roundup-top-stories-for-february-2026/

    Post summary

    CISA has added CVE-2024-49035 to its KEV catalog citing active exploitation in the wild.

    000009
    3 followersView on X
  • mysocAi@MysocAi
    Active Exploitation

    [HIGH] CISA Adds Microsoft and Zimbra Flaws to KEV Catalog CISA adds Microsoft and Zimbra vulnerabilities to KEV; remediation required. CVE: CVE-2024-49035 • APT: N/A • Stat… https://www.cyberscotland.com/wp-content/uploads/2025/02/SC3-Daily-threat-bulletin-26-February-2025.pdf

    Post summary

    CISA has added CVE-2024-49035 to its KEV catalog, indicating that the vulnerability is actively exploited and requires remediation, though specific patch details are not provided.

    000008
    3 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftpartner_center---

Explore more