Info
2026-08-21 02:00Z · last 4h · 16 findings
· glm-5.2:cloud
Threat Brief — 2026-08-21 — Azure & Entra Cloud Vulns Lead
Microsoft's latest security updates introduce a concerning cluster of remotely exploitable vulnerabilities across Azure and M365 cloud services. Two unauthenticated network-based RCE flaws in Microsoft Entra ID and Azure Managed Instance for Apache Cassandra stand out, alongside SSRF-driven privilege escalation in Exchange Online. Several other findings are purely informational acknowledgement updates to previously patched CVEs and require no action.
Top items
- CVE-2026-69836 — Microsoft Entra ID RCE via deserialization of untrusted data. An unauthorized attacker can achieve remote code execution over the network by sending crafted serialized data to Entra ID. This is the highest-severity item in this batch: unauthenticated, network-reachable RCE in a core identity platform. (src: MSRC)
- CVE-2026-65770 — Azure Managed Instance for Apache Cassandra RCE via argument injection. An unauthorized attacker can execute arbitrary code over the network by injecting command-argument delimiters. Like the Entra ID flaw, this requires no prior authentication — patch Cassandra-managed instances immediately. (src: MSRC)
- CVE-2026-65801 — Microsoft Exchange Online EoP via SSRF. An unauthorized attacker can leverage server-side request forgery to elevate privileges over the network. SSRF in Exchange Online could enable lateral movement to internal services or metadata endpoints. (src: MSRC)
- CVE-2026-62834 — Azure Data Factory EoP via cryptographic signature bypass. An unauthorized attacker can elevate privileges over the network by exploiting improper verification of cryptographic signatures. This could allow tampered pipelines or data exfiltration through ADF integration runtimes. (src: MSRC)
- CVE-2026-68789 — Azure SQL Database EoP via SQL injection. An authorized attacker can inject SQL commands to elevate privileges over the network. While authentication is required, SQL injection in a managed database service could lead to data theft or cross-tenant access. (src: MSRC)
- CVE-2026-63509 — Microsoft Fabric EoP via relative path traversal. An authorized attacker can elevate privileges over a network by exploiting relative path traversal in Fabric. Lower priority than the unauthenticated items but still actionable for Fabric-enabled tenants. (src: MSRC)
- CVE-2026-69851 — Microsoft Entra ID EoP via SSRF. An authorized attacker can leverage server-side request forgery to elevate privileges over the network. Paired with the Entra ID RCE above, this SSRF represents a second attack surface in the same identity platform. (src: MSRC)
- CVE-2026-69519 — Azure Stack HCI information disclosure. An unauthorized attacker can disclose information over the network through observable response discrepancies. Likely limited to metadata leakage but worth patching on HCI deployments. (src: MSRC)
- CVE-2026-55013 / CVE-2026-55015 — Windows Remote Help spoofing and DoS. Two local-only vulnerabilities in Remote Help involving uncontrolled search path elements. Both require an authorized attacker with local access — low severity but patch if Remote Help is deployed. (src: MSRC) / (src: MSRC)
- Informational-only updates (no action required). Six CVEs received non-substantive changes — acknowledgement updates or link refreshes for previously patched vulnerabilities: CVE-2026-62728 (CLFS), CVE-2026-61363 (RDP Client), CVE-2026-65786 (DWM), CVE-2026-62754 (Kerberos), CVE-2026-62703 (DWM Core), and CVE-2026-70105 (Word — already patched in August 2026 but omitted from release notes). (src: MSRC)
Themes
- Cloud services under fire. Nine of the ten actionable CVEs target Azure or M365 services (Entra ID, Cassandra MI, Exchange Online, Data Factory, SQL Database, Stack HCI, Fabric). The attack surface is shifting from endpoint OS to managed cloud infrastructure.
- SSRF recurs. Two distinct SSRF vulnerabilities (Exchange Online, Entra ID) appear in the same batch — consistent with the broader trend of attackers abusing server-side request handling to pivot internally.
- Unauthenticated network exploits dominate the high-severity tier. Four CVEs allow unauthorized attackers to achieve RCE or EoP over the network (Entra ID RCE, Cassandra RCE, Exchange Online EoP, Data Factory EoP). Prioritise patching these four above all others.
