Skip to content
Critical Azure Vulnerabilities Affect PostgreSQL and Billing Systems

Critical Azure Vulnerabilities Affect PostgreSQL and Billing Systems

First seen 18 Sep 2026, 16:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 18:54 UTC
  • CVE-2026-62874 has a CVSS score of 10.0 and allows unauthenticated privilege escalation.
  • CVE-2026-85878 allows authorized attackers to elevate privileges in PostgreSQL.
  • The vulnerabilities indicate a significant expansion of the Azure attack surface into financial systems.

On September 18, 2026, Microsoft Azure disclosed two critical vulnerabilities: CVE-2026-85878, an Improper Authorization flaw in Azure Database for PostgreSQL with a CVSS score of 9.9, and CVE-2026-62874, an Insufficient Data Authenticity Verification issue in Azure Billing with a maximum CVSS score of 10.0. Both vulnerabilities allow attackers to elevate privileges, with CVE-2026-62874 being particularly severe as it requires no authentication. This cluster of vulnerabilities extends beyond the identity control plane into data and financial layers, indicating a widening attack surface. The vulnerabilities were confirmed by Tenable and MITRE, but Microsoft had not yet issued an advisory for CVE-2026-62874. The timeline of vulnerabilities includes several critical flaws disclosed during the September Patch Tuesday cycles, with activity intensifying in mid-September. All vulnerabilities were addressed through server-side fixes by Microsoft, requiring no action from customers.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-03
Multiple CVEs published
CVE-2026-83711, CVE-2026-69857, CVE-2026-70352, and CVE-2026-62916 disclosed, affecting Azure identity services.
Tech.Yahoo
2026-09-03
CVE-2026-83711 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-03
CVE-2026-69857 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-03
CVE-2026-70352 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-03
CVE-2026-62916 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
Additional CVEs disclosed
CVE-2026-83941 and CVE-2026-69854 published, further impacting Azure services.
Tech.Yahoo
2026-09-08
CVE-2026-83941 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
CVE-2026-69854 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-17
New vulnerabilities disclosed
CVE-2026-69843, CVE-2026-77903, and CVE-2026-85889 published, indicating ongoing issues in Azure.
Tech.Yahoo
2026-09-17
CVE-2026-69843 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (6)

Following this threat?

Track Microsoft and CVE-2026-62874 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed