CVE-2026-35428General(microsoft / azure_cloud_shell)

LOWCVSS 9.6 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch microsoft azure_cloud_shell systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_cloud_shell

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • General: 5 classified signals
  • Disclosure: 3 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-06-08)
  • 10 total mentions across 5 days

Affected systems

Vendors
Products
azure_cloud_shell

1 version affected across 1 product

Deep dive

Activity timeline10 mentions / 5d
01234Mentions · 2026-05-08: 1Mentions · 2026-05-10: 2Mentions · 2026-05-12: 2Mentions · 2026-05-13: 1Mentions · 2026-06-08: 4Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-06-08: 2Technical Details · 2026-05-10: 2Technical Details · 2026-05-12: 2Technical Details · 2026-06-08: 305-0805-1005-1205-1306-08
Signal classification3 categories
General
550.0%
Disclosure
330.0%
Patch
220.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-05-081
General1
2026-05-102
General2
2026-05-122
Disclosure2
2026-05-131
General1
2026-06-084
Disclosure1General1Patch2
Full discourse10 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    What Happened Microsoft disclosed CVE-2026-35428, a command injection flaw in Azure Cloud Shell that allows unauthenticated attackers to execute arbitrary commands and perform network spoofing. The vulnerability stems from improper neutralization of special elements…

    Post summary

    Microsoft has published details of CVE-2026-35428, a command injection flaw in Azure Cloud Shell that permits arbitrary command execution by unauthenticated attackers, with no indication of active exploitation or available fixes at this time.

    2000055
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Unauthenticated Command Injection in Azure Cloud Shell: CVE-2026-35428 (CVSS 9.6). The flaw was published on May 7, 2026, and Microsoft immediately released an official patch.

    Post summary

    A newly disclosed unauthenticated command injection vulnerability in Azure Cloud Shell (CVE-2026-35428, CVSS 9.6) was quickly patched by Microsoft.

    1000050
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    TL;DR Microsoft patched a critical command injection vulnerability (CVE-2026-35428) in Azure Cloud Shell on May 7, 2026. An unauthenticated attacker can inject arbitrary commands over the network, leading to spoofing and lateral movement within compromised environments. No…

    Post summary

    Microsoft patched CVE-2026-35428, a critical command injection vulnerability in Azure Cloud Shell that could let unauthenticated attackers run arbitrary commands and enable lateral movement. No evidence of active exploitation or PoC was mentioned.

    1000047
    258 followersView on X
  • kawn@kawn2020
    General

    #windowsupdate #microsoft つづき ・CVE-2026-34327 8.2 Microsoft パートナー センター ・CVE-2026-35428 9.6 Azure Cloud Shell ・CVE-2026-40379 9.3 Azure Entra ID ・CVE-2026-41105 8.1 Azure 通知サービス ・CVE-2026-42826 10  Azure DevOps

    Post summary

    The tweet simply lists several newly disclosed CVEs with their CVSS scores and affected Microsoft/Azure products, offering no additional technical or exploitation details.

    10000111
    85 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: The cybersecurity industry is selling you dashboards. CVE: CVE-2026-35428 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE‑2026‑35428 as a critical vulnerability (CVSS 9.6) but provides no PoC, exploit, patch, or evidence of active exploitation.

    1000039
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/2026-05-08-azure-cloud-shell-command-injection-cve-2026-35428 #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The provided content merely references a URL and hashtags about CVE-2026-35428 without detailing any PoC, exploit, patch, or technical specifics.

    0000027
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    https://lyrie.ai/research/research/cve-2026-35428-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The link points to an advisory that discloses details of CVE‑2026‑35428, likely including patch information and technical aspects, but no PoC, exploit code, or evidence of active exploitation is mentioned.

    0000021
    210 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-35428 Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a ne… https://www.cve.org/CVERecord?id=CVE-2026-35428 ----- Traducción: CVE-2026-35428 Neu… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-35428, a command injection flaw in Azure Cloud Shell that allows an unauthorized attacker to perform spoofing, but no further details on PoC, exploitation, or fixes are provided.

    0000038
    76 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-35428 Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a ne… https://www.cve.org/CVERecord?id=CVE-2026-35428

    Post summary

    The post references CVE-2026-35428, a command‑injection vulnerability in Azure Cloud Shell, offering only brief technical detail without evidence of exploitation, PoC, or patches.

    00000213
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-35428 Command Injection in Azure Cloud Shell Enabling Network-Based Spoofing Attacks https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35428

    Post summary

    The snippet only announces the CVE and provides a link for further details, without additional context or actionable information.

    0000057
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_cloud_shell---

Explore more