Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.5

Azure IoT Explorer allows attackers to spoof network requests

CVE-2026-26121
Summary

An attacker can manipulate network requests on your Azure IoT Explorer, potentially allowing them to access unauthorized resources or disrupt your IoT devices. This could lead to data theft or device tampering. Update Azure IoT Explorer to the latest version to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
microsoft azure_iot_explorer <= 0.15.14 –
Original title
Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network.
Original description
Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network.
nvd CVSS3.1 7.5
Vulnerability type
CWE-20 Improper Input Validation
CWE-918 Server-Side Request Forgery (SSRF)
Published: 10 Mar 2026 · Updated: 14 Mar 2026 · First seen: 11 Mar 2026