Microsoft rejects critical Azure vulnerability report, no CVE issued

2026-05-17T01:23:25Zfc9147acfb7ab2e237f0b470778d200bde1ee64f249148b124fe807da6c39d2a
AKSCVE-2026-20182avada-builderazureazure-backupburst-statisticsciscoedgeexchangefunnel-builderkazuarno-cvenode-ipcnpmopenaip2p-botnetpasswords-in-memorypwn2ownremus-infostealersd-wansecret-blizzardsupply-chaintanstackwordpresszero-day

What happened

Multiple high-impact security incidents and active exploits were reported across cloud, supply-chain, endpoint and web ecosystems. Notable items include an alleged silently fixed Azure Backup for AKS issue with no CVE issued, a modularized Kazuar P2P backdoor by Russian threat group Secret Blizzard, active exploitation of WordPress plugin vulnerabilities (Funnel Builder, Avada Builder, Burst Statistics) to steal credentials and payment data, a credential-stealing supply-chain compromise of the node-ipc npm package and related TanStack supply-chain impacts (affecting OpenAI), Microsoft Exchange

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
fc9147acfb7ab2e237f0b470778d200bde1ee64f249148b124fe807da6c39d2a
Enrichment time
2026-05-17T01:23:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.