'; } else{ echo ''; } echo 'Hillstone Networks'; } elseif ($_SERVER[HTTP_HOST] == "update1.huaantech.com.cn") { echo ''; echo 'huaantech'; } elseif ($_SERVER[HTTP_HOST] == "update1.dcnetworks.com.cn") { echo ''; echo 'dcnetworks'; } elseif ($_SERVER[HTTP_HOST] == "update1.w-ibeda.com") { if (false===strpos($_SERVER[REQUEST_URI],"/en/")) echo ''; else echo ''; echo 'w-ibeda'; } elseif ($_SERVER[HTTP_HOST] == "update1.hp-telecom.com") { echo ''; echo 'hp-telecom'; } elseif ($_SERVER[HTTP_HOST] == "update1.maipu.com") { echo ''; echo 'Maipu'; } elseif ($_SERVER[HTTP_HOST] == "update1.ncurity.com") { echo ''; echo 'Ncurity'; } elseif ($_SERVER[HTTP_HOST] == "update1.socusnetwork.com") { echo ''; echo 'Socusnetwork'; } else{ echo ''; echo 'Hillstone Networks'; } ?>
 
   
 

web_app:adx_mcp_table_name_kql_injection(Rule ID:1070210582)

Release Date:2026/7/27

Rule Name:CVE-2026-33980: Azure Data Explorer MCP Server KQL Injection Exploitation

Severity:high

CVE ID:CVE-2026-33980

 

Descripiton:

CVE-2026-33980 is a KQL injection vulnerability affecting Azure Data Explorer MCP Server 0.1.1 and earlier. Untrusted table names are inserted into database queries without sufficient validation, allowing attackers to execute unauthorized KQL queries against the connected cluster.This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None

 

Solution:

Update vendor patches.