Microsoft Azure Cloud Shell是美国微软(Microsoft)公司的一个基于浏览器的云端命令行环境。 Microsoft Azure Cloud Shell存在命令注入漏洞,该漏洞源于命令中特殊元素的中和不当,可能导致未经授权的攻击者通过网络进行欺骗。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Azure Cloud Shell | - |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Azure Cloud Shell | - | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42826 | 10.0 CRITICAL | Azure DevOps Information Disclosure Vulnerability |
| CVE-2026-33109 | 9.9 CRITICAL | Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability |
| CVE-2026-33823 | 9.6 CRITICAL | Microsoft Team Events Portal Information Disclosure Vulnerability |
| CVE-2026-33844 | 9.0 CRITICAL | Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability |
| CVE-2026-32207 | 8.8 HIGH | Azure Machine Learning Notebook Spoofing Vulnerability |
| CVE-2026-35435 | 8.6 HIGH | Azure AI Foundry Elevation of Privilege Vulnerability |
| CVE-2026-34327 | 8.2 HIGH | Microsoft Partner Center Spoofing Vulnerability |
| CVE-2026-41105 | 8.1 HIGH | Azure Monitor Action Group Notification System Elevation of Privilege Vulnerability |
| CVE-2026-26164 | 7.5 HIGH | M365 Copilot Information Disclosure Vulnerability |
| CVE-2026-26129 | 7.5 HIGH | M365 Copilot Information Disclosure Vulnerability |
| CVE-2026-33111 | 7.5 HIGH | Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability |
No comments yet