Tech.Yahoo Critical Azure Vulnerabilities Affect PostgreSQL and Billing Systems
Article Content
- •CVE-2026-62874 has a CVSS score of 10.0 and allows unauthenticated privilege escalation.
- •CVE-2026-85878 allows authorized attackers to elevate privileges in PostgreSQL.
- •The vulnerabilities indicate a significant expansion of the Azure attack surface into financial systems.
On September 18, 2026, Microsoft Azure disclosed two critical vulnerabilities: CVE-2026-85878, an Improper Authorization flaw in Azure Database for PostgreSQL with a CVSS score of 9.9, and CVE-2026-62874, an Insufficient Data Authenticity Verification issue in Azure Billing with a maximum CVSS score of 10.0. Both vulnerabilities allow attackers to elevate privileges, with CVE-2026-62874 being particularly severe as it requires no authentication. This cluster of vulnerabilities extends beyond the identity control plane into data and financial layers, indicating a widening attack surface. The vulnerabilities were confirmed by Tenable and MITRE, but Microsoft had not yet issued an advisory for CVE-2026-62874. The timeline of vulnerabilities includes several critical flaws disclosed during the September Patch Tuesday cycles, with activity intensifying in mid-September. All vulnerabilities were addressed through server-side fixes by Microsoft, requiring no action from customers.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (6)
Following this threat?
Track Microsoft and CVE-2026-62874 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Authentication Bypass Vulnerability Found in Microsoft Fabric A critical authentication bypass vulnerability, CVE-2026-69843, has been discovered in Microsoft Fabric, allowing attackers to exploit the system without credentials or user interaction. This CVSS 10.0 vulnerability utilizes a network attack vector and has a scope-changed metric, enabling adversaries to breach…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…