CVE-2026-23664 is a high-severity information disclosure vulnerability in Microsoft Azure IoT Explorer, rated 7.5 CVSS. This flaw allows an unauthenticated, remote attacker to disclose sensitive information over a network due to improper restriction of communication channels. Exploitation requires low attack complexity and no user interaction. While there is no public exploit code available and it is not known to be actively exploited, the vulnerability has received some community and media attention, notably being addressed in the March 2026 Patch Tuesday updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.15.13CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_iot_explorer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.