CVE-2026-21228: Microsoft Azure Local

High severity, CVSS 8.1. EPSS: 0.8% chance of exploitation in the next 30 days.

Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network.

Affected products

  • Microsoft Azure Local: before 2510.0.3002 (fixed in 2510.0.3002)

Published 2026-02-10. Last modified 2026-06-17.