// Service

Microsoft Azure

Microsoft's cloud platform — Entra ID, AKS, Storage, and the broader Azure stack.

// Alerts

Recent threats

CVE-2026-62911, a critical authentication bypass vulnerability in Microsoft Exchange Server disclosed in August 2026, affects over 21,000 unpatched servers globally. The flaw enables NTLM credential relay attacks on the MRSProxy endpoint, allowing unauthenticated attackers to bypass authentication and, when chained with additional vulnerabilities, achieve pre-authentication remote code execution. A public proof-of-concept has been released, and patches are available from Microsoft but adoption remains slow.

Microsoft reversed its exploitation status for CVE-2026-69836, an Entra ID vulnerability, changing from 'under active exploitation' to 'not exploited.' The vulnerability affects Microsoft Azure Entra ID authentication systems.

CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on August 18, 2026, including CVE-2026-33824 (Windows IKE remote code execution, CVSS 9.8) and CVE-2026-55040 (Microsoft SharePoint authentication bypass, CVSS 9.1). The SharePoint flaw enables unauthenticated attackers to forge authentication tokens and gain administrator access to on-premises SharePoint Server. Rapid7 published a proof-of-concept for CVE-2026-55040 on August 11; exploitation attempts using the PoC were reported within hours. CISA mandated remediation for federal systems by August 21, 2026.

CISA added CVE-2019-1068, a remote code execution vulnerability in Microsoft SQL Server, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The flaw allows attackers to execute code with the privileges of the SQL Server Database Engine service account. CISA mandated remediation by August 29, 2026, and flagged the issue for forensic triage. While the vulnerability dates to 2019, recent exploitation attempts demonstrate ongoing risk to SQL Server instances commonly deployed in Azure environments.

A threat actor using the alias "TheHatman" conducted a large-scale credential-theft campaign targeting Microsoft Azure and Entra ID tenants, exfiltrating millions of corporate employee directory records from major multinational organizations including McDonald's (1.7M+ records), Vodafone (425K+), Tata Consultancy Services (800K+), and others. The stolen data includes display names, employee IDs, corporate emails, user principal names, phone numbers, job titles, department structures, manager relationships, and references to privileged accounts. Attackers obtained access via compromised credentials from infostealer malware, weak authentication, or phishing; the data enables high-precision spear-phishing, business email compromise, and targeted credential harvesting attacks.

Microsoft Entra ID (cloud identity and access management service in Azure) suffered a critical remote code execution vulnerability (CVE-2026-69836) caused by improper deserialization of untrusted data. The vulnerability was actively exploited in the wild before disclosure on August 20, 2026, and required no authentication. Microsoft has already deployed the fix server-side, but organizations should review identity logs and conditional access policies for signs of compromise.

A hacker known as 'TheHatman' claims to have stolen Azure cloud credentials from multiple enterprise tenants and is offering stolen data for sale on underground forums. Compromised datasets reportedly include approximately 1.7 million McDonald's employee records, 800,000 TCS records, 425,000 Vodafone records, 250,000 HCL Technologies records, and over 185,000 InterContinental Hotels Group records. Hudson Rock confirmed the credential theft operation targeting Azure cloud services.

Microsoft SharePoint authentication bypass CVE-2026-55040 is under active exploitation following Rapid7's public disclosure on August 12, 2026. The JWT token validation flaw allows attackers to impersonate SharePoint users without privileges. Weaponized exploit code is already in use against honeypots. When chained with CVE-2026-63520 (SharePoint RCE), the vulnerabilities enable unauthenticated remote code execution. Microsoft patched CVE-2026-55040 in July 2026; administrators should verify patching on SharePoint Enterprise Server 2016 and Server 2019 deployments.

Microsoft disclosed CVE-2026-47299, an elevation-of-privilege vulnerability in the Azure Monitor Agent, on August 11, 2026. However, the advisory lacks critical operational details: affected agent versions and the fixed release version are not publicly identified. Administrators deploying AMA on Azure VMs, scale sets, and Arc-enabled servers cannot definitively determine exposure or remediation without this information, complicating patch management.

Microsoft's August 2026 Patch Tuesday release includes fixes for 421 vulnerabilities, with 62 marked critical. Azure-specific issues patched include CVE-2026-62830 (Azure SRE Agent elevation of privilege), CVE-2026-50516 (Azure Kubernetes Service missing authentication), CVE-2026-50481 (Azure AD privilege escalation), CVE-2026-50515 (Azure Service Bus RCE via deserialization), and CVE-2026-62869 (Azure Entra ID spoofing). One zero-day (CVE-2026-68820 in Windows afd.sys) has been exploited in the wild. Organizations should prioritize patching critical vulnerabilities affecting their deployed Azure services.

CISA confirmed that ransomware gangs are actively exploiting CVE-2026-45659, a high-severity remote code execution vulnerability in Microsoft SharePoint, since early July 2026. The flaw stems from unsafe deserialization and allows low-privilege attackers to execute arbitrary code on unpatched SharePoint Enterprise Server 2016, 2019, and Subscription Edition instances with low-complexity attacks. Organizations should prioritize patching as ransomware operators have incorporated the exploit into active campaigns.

Security researchers disclosed Pass-the-Passkey, an attack family allowing adversaries to impersonate enterprise users and bypass phishing-resistant MFA in Windows 11 and Microsoft Entra ID. The attack exploits weaknesses in WebAuthn implementation: Windows 11 event logs exposed passkey assertion responses, and Entra ID failed to enforce anti-replay controls (challenge uniqueness, session binding, signature-counter verification). Attackers with access to logged assertions can replay them to authenticate as the original user, potentially compromising privileged accounts. Microsoft addressed the Windows logging issue (CVE-2026-34348) by truncating signatures as of July 2026, but Entra ID validation gaps remain.

CVE-2026-68823 is a critical remote code execution vulnerability in Azure Confidential Ledger that exposes a dangerous method allowing authenticated attackers to execute arbitrary code over the network. The vulnerability carries a CVSS score of 9.1 and requires low-privilege authentication to exploit. No public proof-of-concept or patch details were available at time of publication.

Security researcher Justin O'Leary disclosed a confused deputy vulnerability in Microsoft Azure Kubernetes Service (AKS) backup tool that could allow privilege escalation to cluster admin. The flaw enables attackers to bypass access controls through insufficient request source verification. Microsoft reportedly patched the issue silently without public disclosure or acknowledgment.

Wiz Research disclosed CosmosEscape, a critical vulnerability chain in Azure Cosmos DB's Gremlin API that allowed attackers to bypass network isolation controls and access arbitrary customer databases across tenants. The flaw stemmed from insufficient security restrictions in the custom Gremlin query engine, permitting .NET reflection techniques to achieve code execution on the DB Gateway and recover the platform-wide Cosmos Master Key, granting full read/write access to all Cosmos DB accounts globally. Microsoft has remediated the vulnerability, found no evidence of external exploitation, and stated no customer action is required.

Microsoft disclosed CVE-2026-62835, a critical improper authorization vulnerability in Azure Portal on July 24, 2026, with a CVSS score of 9.3. The flaw allows unauthenticated remote attackers to disclose sensitive information via network access with no privileges or user interaction required. Microsoft has released an official fix; the service is auto-patched for Azure Portal users.

Microsoft disclosed CVE-2026-58630, a critical improper access control vulnerability in Azure App Service on July 24, 2026, with a CVSS score of 10. The flaw allows unauthenticated attackers to bypass security boundaries and achieve privilege escalation through network access with no authentication required. No public proof-of-concept or patch details are available at time of disclosure.

Microsoft disclosed CVE-2026-58275, an elevation-of-privilege vulnerability in Azure DNS, on July 23, 2026. The flaw potentially allows authenticated attackers to gain unauthorized privileges in DNS management contexts, affecting organizations using Azure-hosted DNS zones and private DNS infrastructure. No technical details, CVSS score, proof-of-concept, or evidence of active exploitation have been publicly disclosed; Microsoft may have deployed backend mitigations without requiring customer action.

CVE-2026-50522, a critical remote-code-execution vulnerability in Microsoft SharePoint Server, is under active exploitation following the release of a public proof-of-concept exploit. Attackers with Site Owner authentication can execute arbitrary code and steal machine keys for persistent access. The flaw affects all supported on-premises SharePoint versions (Subscription Edition, 2019, and 2016). CISA reports multiple SharePoint vulnerabilities being exploited in coordinated campaigns.

CISA added CVE-2026-58644, a critical deserialization remote-code-execution vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog on July 16, 2026. The flaw affects all supported on-premises versions (Subscription Edition, 2019, and 2016) and allows authenticated attackers to execute arbitrary code with low attack complexity. The vulnerability was actively exploited in the wild before Microsoft patched it on July 14, 2026. CISA mandated federal agencies patch by July 19, 2026.

Microsoft patched CVE-2026-49168, an Important elevation-of-privilege vulnerability in Storage Spaces Direct affecting Windows Server clusters. The flaw allows users with limited permissions to escalate rights to administrator level on affected nodes. No active exploitation has been reported, but the vulnerability affects hyperconverged infrastructure deployments and requires prompt patching across all cluster nodes.

Microsoft released its largest Patch Tuesday on record in July 2026, fixing 622 vulnerabilities including three zero-days. Two zero-days—CVE-2026-56155 in Active Directory Federation Services and CVE-2026-56164 in SharePoint Server—are actively exploited in attacks and allow privilege escalation. A third zero-day, CVE-2026-50661 (BitLocker bypass), was publicly disclosed but not exploited. The patch batch also includes 59 critical vulnerabilities and addresses infrastructure flaws in identity and collaboration systems.

Microsoft patched CVE-2026-50656, a high-severity local privilege escalation flaw in the Malware Protection Engine (mpengine.dll) used by Windows Defender. The vulnerability exploits a race condition to grant SYSTEM-level privileges. A proof-of-concept exploit was published in June 2026 by researcher Nightmare-Eclipse and was confirmed to work on fully patched Windows 10 and 11 systems, demonstrating the urgency of patching.

Threat actor '888' claimed on July 6, 2026, to be selling approximately 35GB of stolen Accenture data including Azure Personal Access Tokens, Azure Storage Access Keys, source code, and configuration files from a compromised development environment. The threat actor provided evidence of authenticated access to Azure DevOps repositories via curl requests and git operations. Accenture acknowledged the incident and stated containment, but organizations using Azure DevOps are advised to rotate credentials and audit repository access.

Microsoft issued a security advisory for CVE-2026-53045, a high-severity Linux kernel flaw in the NVIDIA Tegra124 memory controller driver (CVSS 7.8). The vulnerability, a reversed bit check in the EMC driver, affects Windows Subsystem for Linux 2 (WSL2) and Azure Linux VMs with Tegra124 hardware. Exploitation can cause kernel panics, data corruption, and potentially privilege escalation. Microsoft advises updating WSL kernels and Azure container images.

CISA confirmed on July 2, 2026, that attackers are actively exploiting CVE-2026-45659, a high-severity remote code execution vulnerability in Microsoft SharePoint. The deserialization flaw requires only basic authenticated access (Site Member permissions) and was patched in May 2026. Over 10,000 SharePoint servers remain exposed online, with no visibility into remediation coverage.

Microsoft released patches for CVE-2026-33825 (BlueHammer), a Microsoft Defender privilege escalation vulnerability, on April 14, 2026. CISA added the flaw to its Known Exploited Vulnerabilities catalog on April 22 and has now updated the entry to confirm active exploitation in ransomware campaigns. Authenticated attackers can escalate privileges to disable defenses, move laterally, or prepare systems for encryption. No details on specific ransomware groups have been publicly disclosed.

Threat actors conducted a large-scale password spray campaign targeting Azure CLI between June 12 and 21, 2026, making over 81 million login attempts originating primarily from LSHIY LLC infrastructure. Huntress detected 78 user account compromises across 64 customer organizations, with 2-4 accounts typically breached daily. The attack represents part of a broader surge in credential spray attacks across the cloud services landscape.