Azure vulnerabilities
11 CVEs tracked
Azure appears in this reporting cycle within the context of both direct cloud vulnerabilities and a sophisticated supply chain attack targeting CI/CD environments. The primary event is the compromise of the 'czirker' npm maintainer account, which deployed malicious packages designed to steal Azure tokens from GitHub Actions runners using the Bun runtime to evade detection. Defenders should prioritize patching for CVE-2026-62825 (improper authentication in Azure Key Vault) and CVE-2026-58630 (privilege elevation in Azure App Service), while also monitoring for unauthorized 'id-token: write' usage and unexpected Bun runtime downloads on CI runners.
Azərbaycanca: Azure bu hesabat dövründə həm birbaşa bulud zəiflikləri, həm də CI/CD mühitlərini hədəf alan təchizat zənciri hücumu kontekstində görünür. Əsas hadisə 'czirker' adlı kompromat edilmiş npm təchizatçı hesabı vasitəsilə 20+ paketə yoluxmuş əməliyyatdır; bu hücum GitHub Actions runner-lərdən `Azure` tokenlərini oğurlamaqla yanaşı, `Bun` runtime-dan istifadə edərək aşkarlanmadan yayınmaq üçün nəzərdə tutulub. Müdafiəçilər `CVE-2026-62825` (Azure Key Vault-da zəif autentifikasiya) və `CVE-2026-58630` (Azure App Service-də imtiyaz yüksəltmə) ilə bağlı yamaları prioritetləşdirməli, eyni zamanda CI runner-lərdə icazəsiz `id-token: write` istifadəsi və `Bun` runtime yüklənməsi əlamətlərini axtarmalıdırlar.
This vendor's CVEs11
This hub is built from skopnix's own reporting on Azure: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.