This day 02:00 06:00 10:01 14:01 18:01 22:01
Info  2026-08-07 02:00Z · last 4h · 24 findings · glm-5.2:cloud

Threat Brief — 2026-08-07: Microsoft Cloud Patch Flood

Microsoft dropped 20 new CVEs across its cloud and productivity stack, headlined by two remote code execution flaws in Azure Service Bus and Azure Confidential Ledger. A cluster of seven elevation-of-privilege bugs exploitable by unauthenticated attackers over the network — in Microsoft 365 Admin Center, Azure Kubernetes Service, Azure SQL Database, Teams, Power Apps, and Planetary Computer Pro — raises the most urgent concern. No public exploits or KEV listings have been tagged for any of these yet, but the attack surface spans identity, database, container orchestration, and collaboration services simultaneously.

Top items

Themes

Unauthenticated network attack surface across Azure/M365. Seven of the 20 CVEs allow unauthenticated, network-based privilege escalation — spanning Admin Center, AKS, Azure SQL, Teams, Power Apps, Planetary Computer Pro, and SQL Managed Instance. This is an unusually high ratio of pre-auth bugs in a single Microsoft disclosure batch and should drive immediate patch prioritisation for internet-exposed management interfaces.

Identity layer under pressure. Three separate Entra/AAD vulnerabilities (EoP via MAID in Azure AD, path traversal in Entra Provisioning Service, and spoofing in Entra ID) all touch the identity control plane. Even the authorized-attacker variants carry tenant-wide escalation risk if a low-privilege account is compromised first.

Two RCEs in Azure messaging and ledger services. Azure Service Bus (deserialization) and Azure Confidential Ledger (exposed dangerous function) both permit network-based code execution by authenticated attackers. These services are often treated as trusted infrastructure; RCE undermines that assumption and could facilitate supply-chain-style downstream compromise.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db