Microsoft
Microsoft Azure Devops Server: vulnerabilities and CVEs
Microsoft Azure Devops Server has 40 published vulnerabilities, 1 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs40
Last 12 months1
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21512 | Medium (6.5) | 1.0% | — | Feb 10, 2026 | Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network. |
| CVE-2024-35267 | High (7.6) | 1.6% | — | Jul 9, 2024 | Azure DevOps Server Spoofing Vulnerability |
| CVE-2024-35266 | High (7.6) | 1.6% | — | Jul 9, 2024 | Azure DevOps Server Spoofing Vulnerability |
| CVE-2024-20667 | High (7.5) | 1.4% | — | Feb 13, 2024 | Azure DevOps Server Remote Code Execution Vulnerability |
| CVE-2023-21751 | Medium (6.5) | 0.98% | — | Dec 14, 2023 | Azure DevOps Server Spoofing Vulnerability |
| CVE-2023-36561 | High (7.3) | 0.87% | — | Oct 10, 2023 | Azure DevOps Server Elevation of Privilege Vulnerability |
| CVE-2023-38155 | High (8.1) | 1.3% | — | Sep 12, 2023 | Azure DevOps Server Remote Code Execution Vulnerability |
| CVE-2023-33136 | High (8.8) | 1.7% | — | Sep 12, 2023 | Azure DevOps Server Remote Code Execution Vulnerability |
| CVE-2023-36869 | Medium (6.3) | 0.69% | — | Aug 8, 2023 | Azure DevOps Server Spoofing Vulnerability |
| CVE-2023-21569 | Medium (5.5) | 0.68% | — | Jun 14, 2023 | Azure DevOps Server Spoofing Vulnerability |
| CVE-2023-21565 | High (7.1) | 0.93% | — | Jun 14, 2023 | Azure DevOps Server Spoofing Vulnerability |
| CVE-2023-21553 | High (7.5) | 1.4% | — | Feb 14, 2023 | Azure DevOps Server Remote Code Execution Vulnerability |
| CVE-2023-21564 | High (7.1) | 0.89% | — | Feb 14, 2023 | Azure DevOps Server Cross-Site Scripting Vulnerability |
| CVE-2021-28459 | Medium (6.1) | 2.3% | — | Apr 13, 2021 | Azure DevOps Server Spoofing Vulnerability |
| CVE-2021-27067 | Medium (6.5) | 2.6% | — | Apr 13, 2021 | Azure DevOps Server and Team Foundation Server Information Disclosure Vulnerability |
| CVE-2020-17145 | Medium (5.4) | 1.5% | — | Dec 10, 2020 | Azure DevOps Server and Team Foundation Services Spoofing Vulnerability |
| CVE-2020-17135 | Medium (5.4) | 1.3% | — | Dec 10, 2020 | Azure DevOps Server Spoofing Vulnerability |
| CVE-2020-1325 | Medium (5.4) | 1.6% | — | Nov 11, 2020 | Azure DevOps Server and Team Foundation Services Spoofing Vulnerability |
| CVE-2020-1326 | Medium (5.4) | 1.6% | — | Jul 14, 2020 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'. |
| CVE-2020-1327 | Medium (6.1) | 1.8% | — | Jun 9, 2020 | A spoofing vulnerability exists in Microsoft Azure DevOps Server when it fails to properly handle web requests, aka 'Azure DevOps Server HTML Injection Vulnerability'. |
| CVE-2020-0815 | High (7.5) | 1.8% | — | Mar 12, 2020 | An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Elevation of Privilege… |
| CVE-2020-0758 | High (7.5) | 2.0% | — | Mar 12, 2020 | An elevation of privilege vulnerability exists when Azure DevOps Server and Team Foundation Services improperly handle pipeline job tokens, aka 'Azure DevOps Server and Team Foundation Services Elevation of Privilege… |
| CVE-2020-0700 | Medium (5.4) | 1.3% | — | Mar 12, 2020 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server does not properly sanitize user provided input, aka 'Azure DevOps Server Cross-site Scripting Vulnerability'. |
| CVE-2019-1306 | Critical (9.8) | 17% | — | Sep 11, 2019 | A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution… |
| CVE-2019-1305 | Medium (5.4) | 1.5% | — | Sep 11, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'. |
| CVE-2019-1076 | Medium (5.4) | 1.6% | — | Jul 15, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Team Foundation Server does not properly sanitize user provided input, aka 'Team Foundation Server Cross-site Scripting Vulnerability'. |
| CVE-2019-1072 | Critical (9.8) | 13% | — | Jul 15, 2019 | A remote code execution vulnerability exists when Azure DevOps Server and Team Foundation Server (TFS) improperly handle user input, aka 'Azure DevOps Server and Team Foundation Server Remote Code Execution… |
| CVE-2019-0996 | Medium (6.5) | 1.6% | — | Jun 12, 2019 | A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site request forgery. An attacker who successfully exploited this vulnerability… |
| CVE-2019-0979 | Medium (5.4) | 1.7% | — | May 16, 2019 | A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site… |
| CVE-2019-0971 | Medium (6.5) | 8.5% | — | May 16, 2019 | An information disclosure vulnerability exists when Azure DevOps Server and Microsoft Team Foundation Server do not properly sanitize a specially crafted authentication request to an affected server, aka 'Azure DevOps… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.