Microsoft
Microsoft Azure Devops: vulnerabilities and CVEs
Microsoft Azure Devops has 5 published vulnerabilities, 3 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs5
Last 12 months3
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-37267 | High (8.7) | 0.43% | — | Aug 19, 2026 | Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because the git http.extraheader=AUTHORIZATION parameter is logged without… |
| CVE-2026-42826 | High (7.5) | 1.2% | — | May 7, 2026 | Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-23658 | Critical (9.8) | 0.78% | — | Mar 19, 2026 | Insufficiently protected credentials in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-47158 | Critical (9) | 0.70% | — | Jul 18, 2025 | Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-29813 | Critical (9.8) | 1.7% | — | May 8, 2025 | Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.