CVE-2026-42826Disclosure(microsoft / azure_devops)

HIGHCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch microsoft azure_devops systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_devops

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 26 mentions across 13 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 16 signals
  • Disclosure: 11 classified signals
  • General: 11 classified signals
  • Peaked 7d ago at 6 mentions (2026-05-13); latest day: 2
  • 26 total mentions across 13 days

Affected systems

Vendors
Products
azure_devops

1 version affected across 1 product

Deep dive

Activity timeline26 mentions / 13d
02356Mentions · 2026-05-07: 1Mentions · 2026-05-08: 2Mentions · 2026-05-09: 1Mentions · 2026-05-10: 3Mentions · 2026-05-12: 1Mentions · 2026-05-13: 6Mentions · 2026-05-17: 2Mentions · 2026-05-29: 1Mentions · 2026-05-30: 1Mentions · 2026-05-31: 1Mentions · 2026-06-09: 1Mentions · 2026-06-16: 4Mentions · 2026-08-05: 2PoC Mentioned / Linked · 2026-08-05: 1Exploit Tool / Code · 2026-08-05: 1Active Exploitation · 2026-06-09: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-29: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-10: 2Technical Details · 2026-05-13: 4Technical Details · 2026-05-17: 2Technical Details · 2026-05-29: 1Technical Details · 2026-06-09: 1Technical Details · 2026-06-16: 405-0705-0805-0905-1005-1205-1305-1705-2905-3005-3106-0906-1608-05
Signal classification5 categories
Disclosure
1142.3%
General
1142.3%
Patch
27.7%
Active Exploitation
13.8%
Exploit
13.8%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-05-071
Patch1
2026-05-082
Disclosure1General1
2026-05-091
Disclosure1
2026-05-103
Disclosure2General1
2026-05-121
General1
2026-05-136
Disclosure2General4
2026-05-172
Disclosure1General1
2026-05-291
Patch1
2026-05-301
General1
2026-05-311
General1
2026-06-091
Active Exploitation1
2026-06-164
Disclosure3General1
2026-08-052
Disclosure1Exploit1
Full discourse20 posts
  • ExploitGrid@exploitgrid
    Disclosure

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: EGE-GH-nWj2Sy0 ( CVE-2026-42826 ) EGE-GH-FLy7Zaa ( CVE-2025-71338 ) EGE-GH-lPbsTBU ( CVE-2026-52887 ) EGE-GH-KAmy9Px ( CVE-2026-15409 ) EGE-GH-3TfhoOr ( CVE-2026-69083 ) ..🧵👇

    Post summary

    The post announces five newly disclosed critical exploits, listing only CVE identifiers and internal codes, without providing any technical details, PoC, or evidence of active use.

    1000163
    29 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-48095 2 - CVE-2026-45585 3 - CVE-2026-40369 4 - CVE-2026-42826 5 - CVE-2026-0257 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists the top five trending CVEs without further details or actionable information.

    00020229
    1.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-0257 2 - CVE-2026-48095 3 - CVE-2026-42826 4 - CVE-2026-39987 5 - CVE-2026-0265 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply lists trending CVE identifiers without providing any technical detail, evidence of exploitation, or remedial information.

    01010256
    1.7K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-42826 Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. https://www.cve.org/CVERecord?id=CVE-2026-42826

    Post summary

    The text references CVE-2026-42826, describing it as an information‑disclosure flaw in Azure DevOps that permits unauthorized data exposure over a network. No PoC, exploit, patch, or evidence of active exploitation is provided.

    00020285
    57.8K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Azure DevOps CVE-2026-42826 (CVSS 10) Critical information disclosure vulnerability allowing unauthorized access to sensitive network information in Azure DevOps. Impact: unauthorized attackers may gain access to internal network data and infrastructure details.

    Post summary

    The message announces the Azure DevOps CVE-2026-42826 vulnerability, detailing its high CVSS score, information disclosure nature, and potential for attackers to access internal network data.

    00020101
    152 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] EGE-GH-nWj2Sy0 [CRITICAL/PoC] Linked: CVE-2026-42826 POC-CVE-2026-42826-2026-42826-Microsoft-Azure-DevOps-Information-Disclosure-V... 🔗 https://exploitgrid.net/exploits/60527981-e0a2-4b74-b449-97895c3b146a

    Post summary

    The post announces a critical proof‑of‑concept for CVE‑2026‑42826, providing a link to exploit code on ExploitGrid, but makes no claim of active exploitation or mitigation.

    1000054
    29 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    What Happened On May 7, 2026, Microsoft published CVE-2026-42826, a network-accessible information disclosure vulnerability affecting Azure DevOps. Unlike typical authorization bypasses, this flaw allows an unauthorized attacker to directly disclose sensitive information…

    Post summary

    Microsoft announced CVE-2026-42826, a network‑accessible information disclosure flaw in Azure DevOps that permits unauthorized data disclosure.

    1000031
    288 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    Attack Progression An attacker exploiting CVE-2026-42826 could: Enumerate Azure DevOps instances within a target organization Extract Personal Access Tokens (PATs), deploy keys, or service principal credentials Gain access to private repositories, build artifacts, and…

    Post summary

    The snippet outlines how an attacker can exploit CVE-2026-42826 to enumerate Azure DevOps environments and harvest credentials, but does not provide evidence of active exploitation, patches, or a PoC.

    1000034
    288 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Perfect Storm: Unauthenticated Information Disclosure in Azure DevOps (CVE-2026-42826 CVSS 10.0). TL;DR Microsoft disclosed CVE-2026-42826, a critical information disclosure vulnerability in Azure DevOps with a perfect CVSS 10.0 score.

    Post summary

    Microsoft disclosed a critical Azure DevOps information disclosure vulnerability (CVE‑2026‑42826) with a perfect CVSS 10.0 score, but no PoC, exploitation details, or remediation information were provided.

    1000031
    288 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    TL;DR Microsoft disclosed CVE-2026-42826, a critical information disclosure vulnerability in Azure DevOps with a perfect CVSS 10.0 score. An unauthenticated attacker can expose sensitive information across the network without any credentials or user interaction. Every…

    Post summary

    Microsoft disclosed CVE-2026-42826, a CVSS 10.0 information‑disclosure flaw in Azure DevOps that allows unauthenticated attackers to expose sensitive data without credentials.

    1000034
    288 followersView on X
  • كاسبر سكاي@KasperskyDev
    Patch

    ⚠️ ثغرة كشف معلومات بدرجة الحد الأقصى في خدمة سحابية للتطوير، عُولجت تلقائياً في البنية السحابية المعرّف : CVE-2026-42826 درجة الخطورة : 10.0 (CVSS) - Critical المنتج المتأثر : Azure DevOps الحل : Mitigated server-side, no action needed #CVE #Azure #CloudSecurity

    Post summary

    CVE-2026-42826 is an information disclosure vulnerability in Azure DevOps, rated 10.0 CVSS and already mitigated server‑side; no further action is required.

    01000154
    40.0K followersView on X
  • كاسبر سكاي@KasperskyDev
    Disclosure

    CVE-2026-42826 في Azure DevOps يحصل على CVSS 10.0 وهو أعلى تقييم ممكن في منظومة CVSS.

    Post summary

    The text announces CVE-2026-42826 for Azure DevOps, noting its severe CVSS rating of 10.0, without mentioning PoC, exploit, patch, or active exploitation details.

    10000139
    40.0K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-42826 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE-2026-42826 as a critical vulnerability with a CVSS score of 10, but provides no PoC, exploit code, active exploitation evidence, or mitigation advice.

    1000042
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-42826 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a…

    Post summary

    A newly disclosed Azure DevOps information disclosure vulnerability (CVE-2026-42826) has a CVSS 10 score and is classified as critical, but no PoC, exploit, patch, or active exploitation details are included.

    1000062
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-42826 (CVSS 10) — multiple products. CVE: CVE-2026-42826 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE‑2026‑42826 as a critical vulnerability (CVSS 10) affecting multiple products, with no additional technical or mitigation details.

    1000040
    210 followersView on X
  • kawn@kawn2020
    General

    #windowsupdate #microsoft つづき ・CVE-2026-41096 9.8 Microsoft Windows DNS ・CVE-2026-42823 9.9 Azure Logic Apps ・CVE-2026-42826 10  Azure DevOps ・CVE-2026-42898 9.9 Microsoft Dynamics 365 (オンプレミス)

    Post summary

    The post simply lists several newly disclosed Microsoft CVEs with their CVSS scores, without providing additional context or actionable information.

    10000172
    85 followersView on X
  • kawn@kawn2020
    General

    #windowsupdate #microsoft つづき ・CVE-2026-34327 8.2 Microsoft パートナー センター ・CVE-2026-35428 9.6 Azure Cloud Shell ・CVE-2026-40379 9.3 Azure Entra ID ・CVE-2026-41105 8.1 Azure 通知サービス ・CVE-2026-42826 10  Azure DevOps

    Post summary

    The post lists six Microsoft Azure CVE identifiers along with their severity scores and affected services, but contains no information about exploits, patches, or detailed technical claims.

    10000111
    85 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-42826 — CVSS 10/10 ██████████ Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/rrpqNHRCRg

    Post summary

    The tweet announces a critical Azure DevOps vulnerability (CVE‑2026‑42826) with a CVSS score of 10/10 that exposes sensitive data, and it urges users to apply a patch.

    1000080
    29 followersView on X
  • Wijdan | وجـدان@wijdan2_0
    Active Exploitation

    1- ثغرة بالو ألتو (CVE-2026-0300) • الخطورة: CVSS 9.3 (حرجة جداً) • النوع: Unauthenticated Root RCE • الوضع: تحت الاستغلال الفعلي حالياً من قِبل مجموعات هاكرز متطورة ترعاها دول (CL-STA-1132). • الأثر: اختراق كامل لجدار الحماية المحيط بالشبكة، وتتيح للمهاجم مسح السجلات (Logs) وبناء أنفاق سرية للتحرك داخلياً. 2- ثغرة بريد مايكروسوفت (CVE-2026-42897) • النوع: OWA XSS Zero-Day • الوضع: أضيفت فوراً لكتالوج CISA KEV للثغرات المستغلة. • الأثر: بمجرد فتح إيميل مفخخ عبر الويب، يتم سرقة ملفات تعريف الارتباط والاستيلاء على الجلسة (Session Hijacking) والوصول لصندوق البريد بالكامل، وهي مدخل تقليدي لهجمات الفدية. 3- ثغرة Azure DevOps (CVE-2026-42826) • الخطورة: CVSS 10.0 (الحد الأقصى) • الأثر: تسريب معلومات وبيانات حساسة. خطورتها تكمن في مكانها؛ حيث تهدد سلاسل التوريد البرمجية (Software Supply Chain) عبر كشف مفاتيح السحابة (Cloud Tokens) ورموز الـ CI/CD. 4- وثغرتي الـ Android و NGINX: • Android (CVE-2026-0073): ثغرة RCE تؤكد أن هواتف الموظفين (BYOD) هي الحلقة الأضعف لتجاوز التحقق الثنائي (MFA). • "NGINX Rift" (CVE-2026-42945): ثغرة تجاوز سعة الذاكرة (Heap Buffer Overflow) ظلت مخفية منذ 2008 تهدد خوادم الويب وبيئات الـ Kubernetes. 💡 ماذا يجب على فرق الدفاع (Blue Teams) فعله؟ 1.تصحيح الأنظمة الحرجة فوراً وتطبيق العزل (Segmentation). 2.مراقبة الـ Logs للبحث عن مؤشرات الاختراق (IoCs) مثل أدوات الأنفاق: EarthWorm و ReverseSocks5. #الأمن_السيبراني #ThreatIntelligence #BlueTeam

    Post summary

    The post enumerates multiple critical vulnerabilities that are actively exploited by advanced threat actors, urging immediate patching and monitoring.

    00000221
    696 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-42826: Azure DevOps Information Disclosure Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04gVfdJ0

    Post summary

    The text announces CVE-2026-42826 as an information disclosure issue and directs readers to a response guide, but lacks explicit details on PoC, exploits, or patches.

    0000036
    31 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_devops---

Explore more