CyberICT

CVE-2026-33844

Microsoft · Published May 7, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability. Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

Affected Products

  • Azure Managed Instance for Apache Cassandra

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C