CVE-2026-65818, a server-side request forgery (SSRF) vulnerability in Microsoft Power Automate (CVSS 8.5), was published on September 3, 2026. The flaw allows an authorized attacker with low privileges to elevate privileges over a network through SSRF exploitation. Microsoft has released an official fix; organizations should apply the remediation immediately.
Microsoft Azure
Microsoft's cloud platform — Entra ID, AKS, Storage, and the broader Azure stack.
Recent threats
CVE-2026-62911, a critical authentication bypass vulnerability in Microsoft Exchange Server disclosed in August 2026, affects over 21,000 unpatched servers globally. The flaw enables NTLM credential relay attacks on the MRSProxy endpoint, allowing unauthenticated attackers to bypass authentication and, when chained with additional vulnerabilities, achieve pre-authentication remote code execution. A public proof-of-concept has been released, and patches are available from Microsoft but adoption remains slow.
- Over 21,000 Microsoft Exchange Servers Remain Exposed to Active (opens in a new tab)
- PoC Released for Microsoft Exchange CVE-2026-62911 Pre-Auth RCE (opens in a new tab)
- Nearly 22,000 Microsoft Exchange servers vulnerable to hijack at(opens in a new tab)
- Nearly 22,000 Exchange servers face complete mailbox takeover ri(opens in a new tab)
- Nearly 22,000 Microsoft Exchange servers remain exposed to criti(opens in a new tab)
- 21,000+ Microsoft Exchange Servers Remain Exposed to Active CVE-(opens in a new tab)
Microsoft reversed its exploitation status for CVE-2026-69836, an Entra ID vulnerability, changing from 'under active exploitation' to 'not exploited.' The vulnerability affects Microsoft Azure Entra ID authentication systems.
CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on August 18, 2026, including CVE-2026-33824 (Windows IKE remote code execution, CVSS 9.8) and CVE-2026-55040 (Microsoft SharePoint authentication bypass, CVSS 9.1). The SharePoint flaw enables unauthenticated attackers to forge authentication tokens and gain administrator access to on-premises SharePoint Server. Rapid7 published a proof-of-concept for CVE-2026-55040 on August 11; exploitation attempts using the PoC were reported within hours. CISA mandated remediation for federal systems by August 21, 2026.
CISA added CVE-2019-1068, a remote code execution vulnerability in Microsoft SQL Server, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The flaw allows attackers to execute code with the privileges of the SQL Server Database Engine service account. CISA mandated remediation by August 29, 2026, and flagged the issue for forensic triage. While the vulnerability dates to 2019, recent exploitation attempts demonstrate ongoing risk to SQL Server instances commonly deployed in Azure environments.
- CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux(opens in a new tab)
- CISA Warns of Microsoft SQL Server RCE Vulnerability Exploited i(opens in a new tab)
- CISA Warns of Six Exploited Flaws in Microsoft, Linux and Citrix(opens in a new tab)
- CISA Warns of Actively Exploited Microsoft SQL Server RCE Vulner(opens in a new tab)
A threat actor using the alias "TheHatman" conducted a large-scale credential-theft campaign targeting Microsoft Azure and Entra ID tenants, exfiltrating millions of corporate employee directory records from major multinational organizations including McDonald's (1.7M+ records), Vodafone (425K+), Tata Consultancy Services (800K+), and others. The stolen data includes display names, employee IDs, corporate emails, user principal names, phone numbers, job titles, department structures, manager relationships, and references to privileged accounts. Attackers obtained access via compromised credentials from infostealer malware, weak authentication, or phishing; the data enables high-precision spear-phishing, business email compromise, and targeted credential harvesting attacks.
Microsoft Entra ID (cloud identity and access management service in Azure) suffered a critical remote code execution vulnerability (CVE-2026-69836) caused by improper deserialization of untrusted data. The vulnerability was actively exploited in the wild before disclosure on August 20, 2026, and required no authentication. Microsoft has already deployed the fix server-side, but organizations should review identity logs and conditional access policies for signs of compromise.
- Microsoft Entra ID Remote Code Execution Vulnerability Exploited(opens in a new tab)
- Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Re(opens in a new tab)
- Microsoft warns of max severity Entra ID flaw exploited in attac(opens in a new tab)
- Microsoft sounds alarm as perfect-10 Entra ID flaw comes under a(opens in a new tab)
- Microsoft Says Latest Entra ID Flaw CVE-2026-69836 Exploited(opens in a new tab)
- Microsoft Patches Entra ID RCE Vulnerability Exploited in Attack(opens in a new tab)
A hacker known as 'TheHatman' claims to have stolen Azure cloud credentials from multiple enterprise tenants and is offering stolen data for sale on underground forums. Compromised datasets reportedly include approximately 1.7 million McDonald's employee records, 800,000 TCS records, 425,000 Vodafone records, 250,000 HCL Technologies records, and over 185,000 InterContinental Hotels Group records. Hudson Rock confirmed the credential theft operation targeting Azure cloud services.
- Azure Cloud Credential Theft leads to Data Breach of McDonald’s (opens in a new tab)
- Fortune 500 Companies Hit in Azure Data Theft Campaign - Securit(opens in a new tab)
- Microsoft Azure data breach? Over 3.6 million employee records a(opens in a new tab)
- Week in review: Records allegedly stolen from Azure tenants, Med(opens in a new tab)
Microsoft SharePoint authentication bypass CVE-2026-55040 is under active exploitation following Rapid7's public disclosure on August 12, 2026. The JWT token validation flaw allows attackers to impersonate SharePoint users without privileges. Weaponized exploit code is already in use against honeypots. When chained with CVE-2026-63520 (SharePoint RCE), the vulnerabilities enable unauthenticated remote code execution. Microsoft patched CVE-2026-55040 in July 2026; administrators should verify patching on SharePoint Enterprise Server 2016 and Server 2019 deployments.
- Hackers leverage new Microsoft SharePoint exploit in attacks(opens in a new tab)
- Microsoft SharePoint RCE Vulnerability Lets Remote Attackers Exe(opens in a new tab)
- Attackers Exploit SharePoint Authentication Bypass After Public (opens in a new tab)
- Hackers Actively Exploiting Microsoft SharePoint Vulnerability F(opens in a new tab)
- SharePoint CVE-2026-55040 Actively Exploited: Attackers Forge Ad(opens in a new tab)
- CISA Adds Microsoft SharePoint Weak Authentication Vulnerability(opens in a new tab)
Microsoft disclosed CVE-2026-47299, an elevation-of-privilege vulnerability in the Azure Monitor Agent, on August 11, 2026. However, the advisory lacks critical operational details: affected agent versions and the fixed release version are not publicly identified. Administrators deploying AMA on Azure VMs, scale sets, and Arc-enabled servers cannot definitively determine exposure or remediation without this information, complicating patch management.
Microsoft's August 2026 Patch Tuesday release includes fixes for 421 vulnerabilities, with 62 marked critical. Azure-specific issues patched include CVE-2026-62830 (Azure SRE Agent elevation of privilege), CVE-2026-50516 (Azure Kubernetes Service missing authentication), CVE-2026-50481 (Azure AD privilege escalation), CVE-2026-50515 (Azure Service Bus RCE via deserialization), and CVE-2026-62869 (Azure Entra ID spoofing). One zero-day (CVE-2026-68820 in Windows afd.sys) has been exploited in the wild. Organizations should prioritize patching critical vulnerabilities affecting their deployed Azure services.
- Microsoft Patch Tuesday for August 2026 — Snort rules and promin(opens in a new tab)
- Microsoft and Adobe Patch Tuesday, August 2026 Security Update R(opens in a new tab)
- August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploit(opens in a new tab)
- Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wor(opens in a new tab)
- 421 bugs in Microsoft's Patch Tuesday release, and the Norks hav(opens in a new tab)
- Microsoft August 2026 Patch Tuesday: 421 CVEs Fixed(opens in a new tab)
CISA confirmed that ransomware gangs are actively exploiting CVE-2026-45659, a high-severity remote code execution vulnerability in Microsoft SharePoint, since early July 2026. The flaw stems from unsafe deserialization and allows low-privilege attackers to execute arbitrary code on unpatched SharePoint Enterprise Server 2016, 2019, and Subscription Edition instances with low-complexity attacks. Organizations should prioritize patching as ransomware operators have incorporated the exploit into active campaigns.
Microsoft released patches for CVE-2026-71331, a critical remote code execution vulnerability in Azure Attestation service and Device Health Attestation Service. RCE vulnerabilities allow attackers to execute arbitrary code in the context of affected services. Organizations using Azure Attestation should validate exposure and deploy applicable patches immediately.
Security researchers disclosed Pass-the-Passkey, an attack family allowing adversaries to impersonate enterprise users and bypass phishing-resistant MFA in Windows 11 and Microsoft Entra ID. The attack exploits weaknesses in WebAuthn implementation: Windows 11 event logs exposed passkey assertion responses, and Entra ID failed to enforce anti-replay controls (challenge uniqueness, session binding, signature-counter verification). Attackers with access to logged assertions can replay them to authenticate as the original user, potentially compromising privileged accounts. Microsoft addressed the Windows logging issue (CVE-2026-34348) by truncating signatures as of July 2026, but Entra ID validation gaps remain.
CVE-2026-68823 is a critical remote code execution vulnerability in Azure Confidential Ledger that exposes a dangerous method allowing authenticated attackers to execute arbitrary code over the network. The vulnerability carries a CVSS score of 9.1 and requires low-privilege authentication to exploit. No public proof-of-concept or patch details were available at time of publication.
Security researcher Justin O'Leary disclosed a confused deputy vulnerability in Microsoft Azure Kubernetes Service (AKS) backup tool that could allow privilege escalation to cluster admin. The flaw enables attackers to bypass access controls through insufficient request source verification. Microsoft reportedly patched the issue silently without public disclosure or acknowledgment.
Wiz Research disclosed CosmosEscape, a critical vulnerability chain in Azure Cosmos DB's Gremlin API that allowed attackers to bypass network isolation controls and access arbitrary customer databases across tenants. The flaw stemmed from insufficient security restrictions in the custom Gremlin query engine, permitting .NET reflection techniques to achieve code execution on the DB Gateway and recover the platform-wide Cosmos Master Key, granting full read/write access to all Cosmos DB accounts globally. Microsoft has remediated the vulnerability, found no evidence of external exploitation, and stated no customer action is required.
Microsoft disclosed CVE-2026-62835, a critical improper authorization vulnerability in Azure Portal on July 24, 2026, with a CVSS score of 9.3. The flaw allows unauthenticated remote attackers to disclose sensitive information via network access with no privileges or user interaction required. Microsoft has released an official fix; the service is auto-patched for Azure Portal users.
Microsoft disclosed CVE-2026-58630, a critical improper access control vulnerability in Azure App Service on July 24, 2026, with a CVSS score of 10. The flaw allows unauthenticated attackers to bypass security boundaries and achieve privilege escalation through network access with no authentication required. No public proof-of-concept or patch details are available at time of disclosure.
Microsoft disclosed CVE-2026-58275, an elevation-of-privilege vulnerability in Azure DNS, on July 23, 2026. The flaw potentially allows authenticated attackers to gain unauthorized privileges in DNS management contexts, affecting organizations using Azure-hosted DNS zones and private DNS infrastructure. No technical details, CVSS score, proof-of-concept, or evidence of active exploitation have been publicly disclosed; Microsoft may have deployed backend mitigations without requiring customer action.
CVE-2026-50522, a critical remote-code-execution vulnerability in Microsoft SharePoint Server, is under active exploitation following the release of a public proof-of-concept exploit. Attackers with Site Owner authentication can execute arbitrary code and steal machine keys for persistent access. The flaw affects all supported on-premises SharePoint versions (Subscription Edition, 2019, and 2016). CISA reports multiple SharePoint vulnerabilities being exploited in coordinated campaigns.
- Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation(opens in a new tab)
- Critical SharePoint RCE flaw exploited to steal machine keys(opens in a new tab)
- Another SharePoint RCE exploited: Patch, then rotate your machin(opens in a new tab)
- Critical SharePoint RCE flaw exploited to steal machine keys(opens in a new tab)
- Public PoC triggers active exploitation of critical SharePoint R(opens in a new tab)
- Fourth SharePoint Vulnerability Exploited in Past Month's Wave o(opens in a new tab)
CISA added CVE-2026-58644, a critical deserialization remote-code-execution vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog on July 16, 2026. The flaw affects all supported on-premises versions (Subscription Edition, 2019, and 2016) and allows authenticated attackers to execute arbitrary code with low attack complexity. The vulnerability was actively exploited in the wild before Microsoft patched it on July 14, 2026. CISA mandated federal agencies patch by July 19, 2026.
Microsoft patched CVE-2026-49168, an Important elevation-of-privilege vulnerability in Storage Spaces Direct affecting Windows Server clusters. The flaw allows users with limited permissions to escalate rights to administrator level on affected nodes. No active exploitation has been reported, but the vulnerability affects hyperconverged infrastructure deployments and requires prompt patching across all cluster nodes.
Microsoft released its largest Patch Tuesday on record in July 2026, fixing 622 vulnerabilities including three zero-days. Two zero-days—CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint Server—are actively exploited in attacks and allow privilege escalation. A third zero-day, CVE-2026-50661 (BitLocker bypass), was publicly disclosed but not exploited. The patch batch also includes 59 critical vulnerabilities and addresses infrastructure flaws in identity and collaboration systems.
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zer(opens in a new tab)
- Microsoft Patches Record 622 Flaws, Including Two Zero-Days Unde(opens in a new tab)
- Microsoft Patches Active Directory Flaw That Could Let Attackers(opens in a new tab)
- Microsoft Patches Record 622 Vulnerabilities, Including Two Expl(opens in a new tab)
- Microsoft Patch Tuesday for July 2026 — Snort rules and prominen(opens in a new tab)
- Microsoft rolls out massive Windows 11 security update with 416 (opens in a new tab)
Microsoft patched CVE-2026-50656, a high-severity local privilege escalation flaw in the Malware Protection Engine (mpengine.dll) used by Windows Defender. The vulnerability exploits a race condition to grant SYSTEM-level privileges. A proof-of-concept exploit was published in June 2026 by researcher Nightmare-Eclipse and was confirmed to work on fully patched Windows 10 and 11 systems, demonstrating the urgency of patching.
Threat actor '888' claimed on July 6, 2026, to be selling approximately 35GB of stolen Accenture data including Azure Personal Access Tokens, Azure Storage Access Keys, source code, and configuration files from a compromised development environment. The threat actor provided evidence of authenticated access to Azure DevOps repositories via curl requests and git operations. Accenture acknowledged the incident and stated containment, but organizations using Azure DevOps are advised to rotate credentials and audit repository access.
- Accenture Data Breach Exposes 35GB Source Code and Azure DevOps (opens in a new tab)
- Accenture faces massive data breach that could put clients at ri(opens in a new tab)
- Accenture Confirms Isolated Breach After Hackers Claim 35 GB Sou(opens in a new tab)
- Accenture Confirms Data Breach After Hacker Claims Source Code T(opens in a new tab)
- Accenture acknowledges security incident following 35GB data the(opens in a new tab)
- Cyber Security Newsletter and Bulletin Weekly – 16-Year-Old Linu(opens in a new tab)
Microsoft issued a security advisory for CVE-2026-53045, a high-severity Linux kernel flaw in the NVIDIA Tegra124 memory controller driver (CVSS 7.8). The vulnerability, a reversed bit check in the EMC driver, affects Windows Subsystem for Linux 2 (WSL2) and Azure Linux VMs with Tegra124 hardware. Exploitation can cause kernel panics, data corruption, and potentially privilege escalation. Microsoft advises updating WSL kernels and Azure container images.
CISA confirmed on July 2, 2026, that attackers are actively exploiting CVE-2026-45659, a high-severity remote code execution vulnerability in Microsoft SharePoint. The deserialization flaw requires only basic authenticated access (Site Member permissions) and was patched in May 2026. Over 10,000 SharePoint servers remain exposed online, with no visibility into remediation coverage.
- CISA: Microsoft SharePoint RCE flaw now actively exploited(opens in a new tab)
- U.S. CISA adds a Microsoft SharePoint Server flaw to its Known E(opens in a new tab)
- CISA Warns of Actively Exploited Microsoft SharePoint Vulnerabil(opens in a new tab)
- SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exp(opens in a new tab)
- CISA adds SharePoint flaw to known exploited vulnerabilities lis(opens in a new tab)
- CISA Warns of Actively Exploited Microsoft SharePoint Vulnerabil(opens in a new tab)
Microsoft released patches for CVE-2026-33825 (BlueHammer), a Microsoft Defender privilege escalation vulnerability, on April 14, 2026. CISA added the flaw to its Known Exploited Vulnerabilities catalog on April 22 and has now updated the entry to confirm active exploitation in ransomware campaigns. Authenticated attackers can escalate privileges to disable defenses, move laterally, or prepare systems for encryption. No details on specific ransomware groups have been publicly disclosed.
Threat actors conducted a large-scale password spray campaign targeting Azure CLI between June 12 and 21, 2026, making over 81 million login attempts originating primarily from LSHIY LLC infrastructure. Huntress detected 78 user account compromises across 64 customer organizations, with 2-4 accounts typically breached daily. The attack represents part of a broader surge in credential spray attacks across the cloud services landscape.