CyberICT

CVE-2026-21531

Microsoft · Published February 10, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Azure SDK for Python Remote Code Execution Vulnerability. Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.

Affected Products

  • Azure AI Language Authoring

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C