CVE-2026-21531
Microsoft · Published February 10, 2026
9.8
CVSS v3.1
CRITICALPatch availableGet patch
Description
Azure SDK for Python Remote Code Execution Vulnerability. Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.
Affected Products
- Azure AI Language Authoring
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C