CVE-2018-8529: Microsoft Team Foundation Server

Critical severity, CVSS 9.8. EPSS: 13.5% chance of exploitation in the next 30 days.

A remote code execution vulnerability exists when Team Foundation Server (TFS) does not enable basic authorization on the communication between the TFS and Search services, aka "Team Foundation Server Remote Code Execution Vulnerability." This affects Team.

Affected products

  • Microsoft Team Foundation Server: version 2018 only

Published 2018-11-15. Last modified 2026-06-17.