CyberSecurityBoardThreat Intel · CVEs · Products
Cyber Products

Azure DevOps MCP Server Vulnerability Enables AI Agent Hijacking

July 22, 2026

The official Microsoft Azure DevOps MCP server has a missing prompt-injection guardrail in its pull request tool, allowing attackers to inject hidden commands that AI agents execute.