CVE-2025-47158: Microsoft Azure Devops
Critical severity, CVSS 9.0. EPSS: 0.8% chance of exploitation in the next 30 days.
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
Affected products
- Microsoft Azure Devops: affected versions not specified
Published 2025-07-18. Last modified 2026-06-17.