CyberICT

CVE-2026-35425

Microsoft · Published July 23, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Azure API Management (APIM) Remote Code Execution Vulnerability. Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

Affected Products

  • Azure API Management (APIM)

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C