Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.5
Azure IoT Explorer allows attackers to spoof network requests
CVE-2026-26121
Summary
An attacker can manipulate network requests on your Azure IoT Explorer, potentially allowing them to access unauthorized resources or disrupt your IoT devices. This could lead to data theft or device tampering. Update Azure IoT Explorer to the latest version to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| microsoft | azure_iot_explorer | <= 0.15.14 | – |
Original title
Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network.
Original description
Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network.
nvd CVSS3.1
7.5
Vulnerability type
CWE-20
Improper Input Validation
CWE-918
Server-Side Request Forgery (SSRF)
Published: 10 Mar 2026 · Updated: 14 Mar 2026 · First seen: 11 Mar 2026