What is CVE-2026-73297?
CVE-2026-73297 was found in Microsoft’s open-source UFO framework for intelligent automation. Before version 3.0.8, the `_is_blocked_ip` function in `url_security.py` failed to block transition prefixes like NAT64, 6to4, and Teredo. Attackers could bypass the IP blocking mechanism, so updating to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-73297, Microsoft-un ağıllı avtomatlaşdırma üçün açıq mənbəli UFO çərçivəsində aşkar edilib. 3.0.8 versiyasından əvvəl `url_security.py` modulundakı `_is_blocked_ip` funksiyası NAT64, 6to4 və Teredo kimi keçid prefikslərini bloklaya bilmir. Bu zəiflikdən istifadə edən hücumçular IP bloklama mexanizmini dəf edə bilər, ona görə dərhal son versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: shared vendor: Microsoft
FAQ2
Which versions of the UFO framework are affected by CVE-2026-73297?
This vulnerability affects all versions of the UFO framework prior to 3.0.8.
What can an attacker achieve by exploiting CVE-2026-73297?
An attacker can bypass the IP blocking mechanism in the `_is_blocked_ip` function by using transition prefixes like NAT64, 6to4, and Teredo.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.