Cyber Posture

CVE-2026-33844

Critical

Published: 07 May 2026

Published
07 May 2026
Modified
08 May 2026
KEV Added
Patch
CVSS Score 9.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
EPSS Score 0.0005 16.7th percentile
Risk Priority 18 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-33844 is a critical-severity Improper Input Validation (CWE-20) vulnerability in Microsoft Azure Managed Instance For Apache Cassandra. Its CVSS base score is 9.0 (Critical).

Operationally, ranked at the 16.7th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

Threat & Defense Details

Likely Mitigating ControlsAI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-20

Security testing and developer training directly verify and enforce proper input validation, reducing exploitability of injection and malformed-data weaknesses.

addresses: CWE-20

Security testing and evaluation at multiple SDLC stages directly detects missing or flawed input validation, with the required remediation process ensuring fixes are applied.

addresses: CWE-20

Directly implements checks on information inputs to reject invalid data before processing.

addresses: CWE-20

Spam protection mechanisms perform filtering and detection on inbound/outbound messages, directly compensating for missing or weak input validation of unsolicited content.

NVD Description

Improper input validation in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

Deeper analysisAI

Automated synthesis unavailable for this CVE.

Details

CWE(s)

Affected Products

microsoft
azure managed instance for apache cassandra
all versions

CVEs Like This One

CVE-2026-33109Same product: Microsoft Azure Managed Instance For Apache Cassandra
CVE-2026-20856Same vendor: Microsoft
CVE-2026-26106Same vendor: Microsoft
CVE-2026-27913Same vendor: Microsoft
CVE-2026-32168Same vendor: Microsoft
CVE-2026-21229Same vendor: Microsoft
CVE-2025-21370Same vendor: Microsoft
CVE-2026-26170Same vendor: Microsoft
CVE-2026-20951Same vendor: Microsoft
CVE-2026-20967Same vendor: Microsoft

References