SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2026-33117

In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks.

CRITICAL 9.1EPSS 0.48%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.48%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The Java Key Vault Keys library in the Azure SDK for Java contains an issue in the local cryptographic verification path where authentication tag comparison was implemented incorrectly. In affected applications that use the vulnerable local cryptography path, specially crafted encrypted input may bypass integrity verification checks. Operations delegated to the Key Vault service are not affected. The issue is addressed in version 4.10.6.

CVSS 3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
0.48% probability · 40th percentile
CISA KEV
Not listed
Weakness
CWE-287, CWE-347
Affected
microsoft/azure sdk for java
Source
secure@microsoft.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.