Published · 2d agoSecurity3 min read
Six 10.0s in the control plane, and nothing in your patch queue to show for it
Microsoft shipped 22 updates, six of them scored 10.0, mostly in Entra ID, Exchange Online and Azure. Fixed server-side is not the same as verified in your tenant.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Microsoft on Thursday announced the rollout of 22 new security updates that resolve severe vulnerabilities across multiple products.
- Most of the patches address critical and high-severity flaws in Microsoft Azure, Entra ID, Exchange, Fabric, and Partner Center products.
- An elevation of privilege bug in Azure SQL Database, CVE-2026-69502, has a CVSS score of 10/10.
- Elevation of privilege bugs in Azure Arc, CVE-2026-69555 and CVE-2026-65816, each have a CVSS score of 10/10.
- An elevation of privilege bug in Exchange Online, CVE-2026-65801, has a CVSS score of 10/10.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Microsoft announced 22 new security updates on Thursday, resolving severe vulnerabilities across multiple products, most of them critical and high-severity flaws in Azure, Entra ID, Exchange, Fabric and Partner Center [1][2]. Six of the named defects carry a CVSS score of 10 out of 10, and every one of them sits in a cloud service rather than on a machine you own [8].
The list is worth reading slowly. Elevation of privilege in Azure SQL Database (CVE-2026-69502) [3], two in Azure Arc (CVE-2026-69555 and CVE-2026-65816) [4], one in Exchange Online (CVE-2026-65801) [5], remote code execution in Azure Managed Instance for Apache Cassandra (CVE-2026-65770) [6], and remote code execution in Entra ID (CVE-2026-69836) [7]. Seven further critical elevation-of-privilege issues were fixed in Azure SQL Database, Microsoft Fabric, Entra ID, Azure Logic Apps and Azure Data Factory [9], bringing the named critical count to thirteen [10]. Azure SQL Database alone accounts for four of those thirteen [11]. High-severity fixes also landed in Azure Virtual Machines, Partner Center, Azure Data Factory, Azure Stack HCI, Azure Data Manager for Energy, Copilot in Azure and Windows Remote Help Defense [12].
Then the sentence that decides how your week goes: no customer action is required for the majority of these defects, because Microsoft deployed the mitigations server-side [13]. That is operationally convenient and analytically useless. A 10.0 elevation of privilege in Exchange Online or a remote code execution path into Entra ID is a compromise of the identity control plane [5][7]. If it was exploitable before the server-side fix, the consequence was tokens, app registrations, consent grants and directory roles, none of which are cleaned up by a patch. You get no KB to confirm, no build number to compare, and no way to establish from your side whether anything reached your tenant before the mitigation shipped. The absence of a patching task is being reported as the absence of exposure, and those are different facts.
The contrast inside the same week makes the point sharper. Microsoft fixed a high-severity command injection bug in Copilot, remotely exploitable for information disclosure, tracked as CVE-2026-24301 [14]. It also confirmed it is still working on a fix for ShieldBreak, a zero-day Defender exploit dropped on August 2026 Patch Tuesday by the researcher Nightmare Eclipse, also known as Chaotic Eclipse [15]. Microsoft assesses the underlying flaw as high severity, now CVE-2026-69414 at CVSS 7.8 [16]. "Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as 'ShieldBreak'. We are working to provide a high-quality security update that addresses this vulnerability," the company said [17]. So the issue with public exploit code and a 7.8 is the one still open, and the six perfect scores are already closed without anybody outside Redmond touching them [8][13][16].
What to watch: whether Microsoft publishes any exploitation assessment or tenant-level indicators for the 10.0 Entra ID and Exchange Online bugs, rather than only the score [5][7]. Watch the ShieldBreak timeline, since a Defender privilege-escalation with a public exploit and no update is the item that actually needs local compensating controls [15][16]. And watch Azure SQL Database, which produced four critical elevation-of-privilege findings in a single batch [11].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Microsoft on Thursday announced the rollout of 22 new security updates that resolve severe vulnerabilities across multiple products.
ReportedView cited source - [2]
Most of the patches address critical and high-severity flaws in Microsoft Azure, Entra ID, Exchange, Fabric, and Partner Center products.
ReportedView cited source - [3]
An elevation of privilege bug in Azure SQL Database, CVE-2026-69502, has a CVSS score of 10/10.
ReportedView cited source - [4]
Elevation of privilege bugs in Azure Arc, CVE-2026-69555 and CVE-2026-65816, each have a CVSS score of 10/10.
ReportedView cited source - [5]
An elevation of privilege bug in Exchange Online, CVE-2026-65801, has a CVSS score of 10/10.
ReportedView cited source - [6]
A remote code execution flaw in Azure Managed Instance for Apache Cassandra, CVE-2026-65770, has a CVSS score of 10/10.
ReportedView cited source
Sources & coverage · 4 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- securityweek.comIonut Arghire2d agoMicrosoft Rolls Out 22 Fresh Security Patches
- thehackernews.com2d agoMicrosoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution
- thecyberexpress.comMihir Bagwe2d agoMicrosoft Says CVSS 10.0 Entra ID Code Execution Flaw Was Exploited Before Server-Side Fix



