CVE-2026-33833: Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.
Added to the CISA Known Exploited Vulnerabilities catalog on 12 May 2026. Vendor: AI/ML. Product: machine learning. CVSS score: 8.2.
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.
Required action: Review and patch if applicable to your AI infrastructure.