What is CVE-2026-35425?
CVE-2026-35425 is an improper access control vulnerability in Azure API Management (APIM). It allows an authorized attacker to execute code over a network. Affected users should immediately apply the security update provided by Microsoft.
Azərbaycanca: CVE-2026-35425, Azure API Management (APIM) xidmətində düzgün olmayan giriş nəzarəti zəifliyidir. Bu, şəbəkə üzərindən səlahiyyətli bir hücumçuya kod icrasına imkan verir. Təsirə məruz qalan istifadəçilər Microsoft tərəfindən yayımlanmış təhlükəsizlik yeniləməsini dərhal tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: Azure
FAQ2
Does an attacker need to be authenticated to exploit CVE-2026-35425 in Azure API Management?
Yes, the context states that this vulnerability allows an authorized attacker to execute code over a network.
What mitigation does Microsoft recommend for CVE-2026-35425?
Microsoft recommends that affected users immediately apply the security update provided by them.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.