PT-2026-2765 · Microsoft · Azure Core

·

CVE-2026-21226

·

Published

2026-01-13

·

Updated

2026-07-13

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Azure Core shared client library for Python (affected versions not specified)
Description The deserialization of untrusted data in the Azure Core shared client library for Python allows an authorized attacker to execute code over a network. This flaw enables an attacker with network access to potentially achieve remote code execution (RCE).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00805
CLEANSTART-2026-AN24336
CLEANSTART-2026-FU07345
CLEANSTART-2026-KE11953
CLEANSTART-2026-NM83456
CLEANSTART-2026-QE89118
CVE-2026-21226
GHSA-JM66-CG57-JJV5
OPENSUSE-SU-2026:10161-1
OPENSUSE-SU-2026:20292-1
PYSEC-2026-1208
SUSE-RU-2026:2237-1
SUSE-RU-2026:2237-2
SUSE-SU-2026:0476-1
SUSE-SU-2026:20617-1
SUSE-SU-2026:20621-1

Affected Products

Azure Core