Skip to main content

CVE-2026-35425

Azure API Management (APIM) Remote Code Execution vulnerability

Microsoft·Azure API Management (APIM) Remote Code Execution

MSRC advisory July 23, 2026

Alert details

Source feed
Microsoft MSRC
CVE ID
CVE-2026-35425
Affected products
Azure API Management (APIM) Remote Code Execution · Microsoft Azure API Management (APIM) Remote Code Execution · Microsoft

What happened

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

What it means for your business

Azure API Management (APIM) Remote Code Execution vulnerability (CVE-2026-35425) was added to Microsoft’s security update guidance. Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

EPSS probability

0.48%

Sources

Related briefs

Microsoft MSRC

CVE-2026-50341

Windows NTFS Information Disclosure vulnerability

Windows NTFS Information Disclosure vulnerability (CVE-2026-50341) was added to Microsoft’s security update guidance. Acknowledgement Updated PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-24304

Azure Resource Manager Elevation of Privilege vulnerability

Azure Resource Manager Elevation of Privilege vulnerability (CVE-2026-24304) was added to Microsoft’s security update guidance. Informational Change. CVE ID stays the same. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-54128

Windows DHCP Client Remote Code Execution vulnerability

Windows DHCP Client Remote Code Execution vulnerability (CVE-2026-54128) was added to Microsoft’s security update guidance. Updated an acknowledgement. This is an informational change only. PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Microsoft MSRC

CVE-2026-55129

Microsoft Office Remote Code Execution vulnerability

Microsoft Office Remote Code Execution vulnerability (CVE-2026-55129) was added to Microsoft’s security update guidance. Acknowledgement Updated PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Need help patching?

PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.