CVE-2026-35425
Microsoft · Published July 23, 2026
8.0
CVSS v3.1
HIGHPatch availableGet patch
Description
Azure API Management (APIM) Remote Code Execution Vulnerability. Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
Affected Products
- Azure API Management (APIM)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C