Azure Kubernetes Service
Vendor:
First CVE: Jan 12, 2021 · Active for 5 years
9
Total CVEs
More Total CVEs than 88% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
8.1
Avg CVSS
Higher Avg CVSS than 74% of tracked products
11.1%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Azure Kubernetes Service over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 12, 2021
5 years ago
Most Recent CVE
Jun 9, 2026
49 days ago
CVE Severity & Scoring
Azure Kubernetes Service9 CVEs
33%
22%
44%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (22.2%)
Network6 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (11.1%)
Attack Complexity
Low7 (77.8%)
High2 (22.2%)
Unknown0 (0.0%)
User Interaction
None8 (88.9%)
Unknown0 (0.0%)
Required1 (11.1%)
Privileges Required
Low3 (33.3%)
High1 (11.1%)
None5 (55.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2026-33105CRITICAL Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | Apr 3, 2026 | 10.0 | 39 | NO | NO |
CVE-2026-32193HIGH Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally. | Jun 9, 2026 | 8.8 | 37 | NO | NO |
CVE-2023-29332CRITICAL Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | Sep 12, 2023 | 9.8 | 32 | NO | NO |
CVE-2024-21376CRITICAL Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability | Feb 13, 2024 | 9.0 | 28 | NO | NO |
CVE-2024-21403CRITICAL Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | Feb 13, 2024 | 9.0 | 25 | NO | NO |
CVE-2021-24109MEDIUM Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | Feb 25, 2021 | 6.8 | 22 | NO | NO |
CVE-2021-27075MEDIUM Azure Virtual Machine Information Disclosure Vulnerability | Mar 11, 2021 | 6.8 | 21 | NO | NO |
CVE-2021-1677MEDIUM Azure Active Directory Pod Identity Spoofing Vulnerability | Jan 12, 2021 | 5.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
1 CVE
11.1% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Azure Kubernetes Service
Top CWEs
Versions
No cataloged versions.