Summary
Microsoft issued an out-of-band update on September 3, 2026, fixing nine cloud-platform vulnerabilities (eight critical, including two CVSS 10.0 flaws in Azure AD B2C and Azure AI Language Authoring), with the most consequential being two Entra ID bypasses. All were patched server-side with no customer action needed. The exposure duration is not clear.
Take Action:
Microsoft already fixed all nine flaws on their side, so there's nothing for you to patch. Since attackers may have had a window before the fix, review your Entra ID and Azure sign-in logs and check for any unexpected new admin roles, app registrations, or service principals over the past few months. Don't assume your identity provider is safe by default: turn on alerting for unusual logins and privilege changes, and cut back permissions on service principals and apps to only what they actually need.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)