Microsoft rejects critical Azure vulnerability report, no CVE issued
2026-05-17T01:23:25Z•fc9147acfb7ab2e237f0b470778d200bde1ee64f249148b124fe807da6c39d2a
AKSCVE-2026-20182avada-builderazureazure-backupburst-statisticsciscoedgeexchangefunnel-builderkazuarno-cvenode-ipcnpmopenaip2p-botnetpasswords-in-memorypwn2ownremus-infostealersd-wansecret-blizzardsupply-chaintanstackwordpresszero-day
What happened
Multiple high-impact security incidents and active exploits were reported across cloud, supply-chain, endpoint and web ecosystems. Notable items include an alleged silently fixed Azure Backup for AKS issue with no CVE issued, a modularized Kazuar P2P backdoor by Russian threat group Secret Blizzard, active exploitation of WordPress plugin vulnerabilities (Funnel Builder, Avada Builder, Burst Statistics) to steal credentials and payment data, a credential-stealing supply-chain compromise of the node-ipc npm package and related TanStack supply-chain impacts (affecting OpenAI), Microsoft Exchange
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- fc9147acfb7ab2e237f0b470778d200bde1ee64f249148b124fe807da6c39d2a
- Enrichment time
- 2026-05-17T01:23:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.