CVE-2019-1306: Microsoft Azure Devops Server
Critical severity, CVSS 9.8. EPSS: 17% chance of exploitation in the next 30 days.
A remote code execution vulnerability exists when Azure DevOps Server (ADO) and Team Foundation Server (TFS) fail to validate input properly, aka 'Azure DevOps and Team Foundation Server Remote Code Execution Vulnerability'.
Affected products
- Microsoft Azure Devops Server: version 2019 only; version 2019.0.1 only
- Microsoft Team Foundation Server: version 2018 only
Published 2019-09-11. Last modified 2026-06-17.