< Back to all clusters
[TECHNOLOGY] · 4 sources

started · updated

Microsoft discloses nine vulnerabilities including two critical CVSS 10.0 flaws

Microsoft disclosed nine vulnerabilities on September 3, 2026, including seven critical flaws. Two vulnerabilities, CVE-2026-83711 and CVE-2026-70352, received a CVSS 10.0 rating. The former involves an authorization bypass in Azure AD B2C, while the latter is a missing authentication flaw in Azure AI Language Authoring.

Additional critical vulnerabilities were identified within the Microsoft Entra ID stack, specifically CVE-2026-83941 and CVE-2026-62916, which involve authentication and authorization bypasses. Reports indicated that CVE-2026-62916 may have been subject to pre-patch exploitation.

The disclosure also included high-severity flaws in Microsoft Copilot Studio (CVE-2026-80098), affecting cryptographic signature verification, as well as vulnerabilities in Fabric, Cosmos DB, Power Automate, and Discovery Studio. Many of these issues stem from improper validation in authentication and authorization protocols.

Entities

Azure AD B2C · Microsoft · Microsoft Copilot Studio · Microsoft Entra ID · authentik