Back threataft.com Threataft Blog News Aug 21, 2026 Microsoft Azure Mass Disclosure - CVSS 10.0 Peak | ThreatAft threataft.com Open source
Microsoft released a set of security updates addressing critical and high-severity vulnerabilities across Azure, Entra ID, Exchange, Fabric, and Partner Center. Five of these CVEs carry CVSS 10.0 scores, including remote code execution in Azure Managed Instance for Apache Cassandra, elevation-of-privilege flaws in Azure Arc and Exchange Online, and a deserialization RCE in Entra ID. Microsoft has applied server-side mitigations for most issues, so many customers do not need to act immediately. Administrators should review advisory details to confirm whether any client-side patches apply to their environments.
📌 TL;DR — Microsoft Azure Mass Disclosure: 12 Patches, 5 CVSS 10.0
What happened: Microsoft released security updates addressing vulnerabilities across Azure, Entra ID, Exchange, Fabric, and Partner Center. Five CVEs carry CVSS 10.0 scores. Critical patches: Azure Arc EoP ( CVE-2026-69555 , CVE-2026-65816 , 10.0); Exchange Online EoP ( CVE-2026-65801 , 10.0); Azure Managed Instance for Apache Cassandra RCE ( CVE-2026-65770 , 10.0); Entra ID RCE ( CVE-2026-69836 , 10.0). Impact: RCE, privilege escalation, data theft, service disruption. Affected products: Azure SQL Database, Azure Arc, Entra ID, Exchange Online, Azure Managed Instance for Apache Cassandra, Microsoft Fabric, Azure Logic Apps, Azure Data Factory, and more. Active exploitation: No public exploitation confirmed at time of publication. Defender actions: Microsoft has deployed server-side mitigations for most issues. Review advisory details to confirm whether any client-side patches apply to your environment.
Weakness Types: CWE-20 (Improper Input Validation), CWE-502 (Deserialization of Untrusted Data), CWE-269 (Improper Privilege Management).
⚠️ Server-Side Mitigations Deployed: Microsoft has applied server-side fixes for most issues. Review advisory details to confirm whether any client-side patches apply to your environment.
CVE-2026-69555 and CVE-2026-65816 are CVSS 10.0 elevation-of-privilege vulnerabilities in Azure Arc, Microsoft's hybrid and multi-cloud management service. Both have been mitigated server-side.
CVE-2026-65801 (CVSS 10.0) is an elevation-of-privilege vulnerability in Exchange Online. Server-side mitigations have been applied.
CVE-2026-65770 (CVSS 10.0) is a remote code execution vulnerability in Azure Managed Instance for Apache Cassandra.
The vulnerability stems from improper handling of parameters, allowing an unauthenticated attacker to execute arbitrary code over the network. The CVSS vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H indicates network exploitability, low complexity, no privileges required, no user interaction, changed scope, and complete impact. Microsoft has deployed server-side mitigations.
CVE-2026-69836 (CVSS 10.0) is a remote code execution vulnerability in Microsoft Entra ID (formerly Azure Active Directory).
The flaw is a deserialization vulnerability where the service fails to properly validate untrusted data when converting it back into objects or executable structures, allowing an attacker to execute arbitrary code via a network request. No public exploitation has been confirmed at the time of publication. Microsoft has deployed server-side mitigations.
The following additional vulnerabilities were also patched in this release:
Microsoft has already deployed server-side mitigations for the vast majority of these vulnerabilities . However, administrators should take the following steps:
Review Microsoft's security advisories for your specific environment.
Confirm whether any client-side patches apply to your environment.
Monitor Entra ID logs for unusual authentication events, token issuance anomalies, or unexpected role changes.
Review Azure Arc and Azure SQL Database configurations for any unauthorized changes.
Microsoft released security updates across Azure, Entra ID, Exchange, Fabric, and Partner Center. Five CVEs carry a CVSS 10.0 score: two in Azure Arc, one in Exchange Online, one in Cassandra, and one in Entra ID.
Microsoft has already deployed server-side mitigations for the vast majority of these issues, so many customers do not need to act immediately. Administrators should review the advisory to confirm whether any client-side patches apply to their environments.
Review Microsoft security advisories. Confirm whether any client-side patches apply to your environment. Monitor Entra ID logs for unusual activity.
— The ThreatAft Security Team
ThreatAft is an independent security publication. This analysis is based on research published by Microsoft and NVD as of August 2026. Vulnerability information is time-sensitive; always refer to official sources for the most current guidance.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
