ChangeIntelIT change radar
Public mode

No tenant, Graph, or device access. Every item links to its source. What this means

Some sources or documents need attention: 215/216 feeds/APIs · 387/387 docs · synced 00:17 UTC Customize Public modeDiscuss ChangeIntel on Discord

Azure API Center Information Disclosure Vulnerability

Assessment

Exposure of sensitive information to an unauthorized actor in Azure API Center allows an unauthorized attacker to disclose information over a network.

Severity
Critical
CVSS base score
8.7CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C
Impact
Information Disclosure
EPSS, next 30 days
Not scored yet
Public exploit code
No Nuclei template lists it
Exploitability
Not assessed
Publicly disclosed
No
Customer action
Not required (service-side fix)
Component
Azure API Center
Weakness
—
Issued by
Microsoft
Published
8 Oct 2026 · October 2026
Last revised
8 Oct 2026

Updates that fix it

0 KBs

No KB listed

MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.

Affected products

Apps
1 affected product
ChangeIntel

An IT change radar: releases, security, known issues, retirements, documentation changes, and service status from public sources. Every item links to supporting evidence; dates and statuses can change after they are read.

Sources read 9 Oct 00:17 UTC · 215 of 216 readable · documentation 387/387 current