CVE-2026-33117Patch(microsoft / azure_sdk_for_java)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft azure_sdk_for_java systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_sdk_for_java

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-05-12); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
azure_sdk_for_java

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-12: 1Mentions · 2026-05-13: 1Mentions · 2026-05-16: 1Patch / Workaround · 2026-05-12: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-16: 105-1205-1305-16
Signal classification3 categories
Patch
133.3%
Disclosure
133.3%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-121
Patch1
2026-05-131
Disclosure1
2026-05-161
General1
Full discourse3 posts
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    Disclosure

    CVE-2026-33117 (Azure SDK for Java) is a critical improper-authentication flaw affecting DPI via Azure service access. See full analysis: https://github.com/alan-turing-institute/cyber-threat-observatory/blob/main/reports/2026-05-12/TIER_2_CVE-2026-33117.md #CyberSecurity #DigitalIdentity #DPI #Azure #CloudSecurity

    Post summary

    The text announces CVE‑2026‑33117, a critical improper‑authentication vulnerability in Azure SDK for Java, with a GitHub link to a detailed analysis.

    01002166
    43 followersView on X
  • z3n@zench4n
    General

    Look at the patterns in recent CVEs. Whether it is improper authentication in SDKs like CVE-2026-33117 or unauthenticated RCE in CMS platforms, the root cause is often a failure to validate the boundary between untrusted input and privileged execution.

    Post summary

    The tweet reflects on patterns seen in recent CVEs, noting improper authentication and unauthenticated RCE as common root causes, but does not reveal any deeper technical or exploitation information.

    1000010
    1.4K followersView on X
  • WindowsForum@windowsforum
    Patch

    🪟 CVE-2026-33117 in Azure SDK for Java is your reminder that Windows patching is only half the story. Dependency “security bypass” means the real risk starts in dev, not desktop. #Windows #Security https://windowsforum.com/threads/cve-2026-33117-patch-guidance-for-azure-sdk-for-java-security-bypass.417702/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #CvePatching #AzureSdkJava #JavaDependencyHygiene https://t.co/dHnXfMBldl

    Post summary

    The post highlights CVE‑2026‑33117 in Azure SDK for Java and points to patch guidance, but offers no PoC, active exploitation claims, or detailed technical data.

    0000035
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_sdk_for_java---

Explore more