« Back to list

Microsoft

Microsoft Azure Devops: vulnerabilities and CVEs

Microsoft Azure Devops has 5 published vulnerabilities, 3 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs5
Last 12 months3
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2020-37267High (8.7)0.43%—Aug 19, 2026
Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION parameter is logged without…
CVE-2026-42826High (7.5)1.2%—May 7, 2026
Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.
CVE-2026-23658Critical (9.8)0.78%—Mar 19, 2026
Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-47158Critical (9)0.70%—Jul 18, 2025
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-29813Critical (9.8)1.7%—May 8, 2025
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application1
  2. T1552.001 Credentials In Files1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Microsoft