Skip to content
Beveiligingsnieuws

22 security patches from Microsoft: CVSS 10 updates

22 security patches

Microsoft has announced that 22 security patches will be deployed to address critical vulnerabilities across multiple Microsoft products. The updates focus mainly on environments around Azure, Entra ID, Exchange, Fabric and Partner Center. Some of the fixes have a very high impact rating: multiple issues receive a CVSS 10/10.

In this article, you’ll read which systems are affected the most, what the difference is between vulnerabilities with maximum severity, and what your organization can do to make sure your environment stays secure.

Which products are affected by 22 security patches?

The latest patch round includes 22 updates for both critical and high-severity problems. Microsoft states that the focus is on platforms and management tools that many organizations use for identity, messaging and cloud services.

Specifically, this includes updates for:

  • Azure services (including Azure SQL Database, Azure Arc, and various data and integration components)
  • Entra ID (identity and access management)
  • Exchange Online
  • Microsoft Fabric
  • Microsoft Partner Center
  • Windows Remote Help Defense

In addition, Microsoft also mentions fixes in components such as Azure Virtual Machines, Azure Data Factory and Azure Stack HCI.

CVSS 10/10: the most serious fixes explained

Among the 22 security patches are multiple vulnerabilities Microsoft classifies as extremely severe. The biggest attention goes to issues with CVSS 10/10, as those typically indicate a combination of factors such as impact and exploitability.

Elevation of Privilege (EoP) with CVSS 10/10

Microsoft lists multiple elevation of privilege issues in different Azure components. This type of vulnerability can help attackers increase privileges and thereby gain access to actions that are normally not allowed.

  • Azure SQL Database: CVE-2026-69502
  • Azure Arc: CVE-2026-69555 and CVE-2026-65816
  • Exchange Online: CVE-2026-65801

There are also seven other critical EoP issues, including CVE-2026-68782 and CVE-2026-68789 (both for Azure SQL Database), plus CVE-2026-69851 (Entra ID), CVE-2026-63509 (Microsoft Fabric), and more Azure-related CVEs.

RCE with CVSS 10/10: Remote Code Execution

In addition to EoP, there’s also a category with the most serious threat profile: remote code execution (RCE). Microsoft mentions RCE vulnerabilities in:

  • Azure Managed Instance for Apache Cassandra: CVE-2026-65770
  • Entra ID: CVE-2026-69836

Where EoP mainly involves increasing privileges, RCE can mean the extent to which an attacker can run arbitrary code. That makes this kind of vulnerability typically especially urgent in risk analyses.

What does this mean for you? (and what has often already been done)

One key point from the announcement is that Microsoft says that for the majority of these security issues, no customer action is required. The reason: Microsoft has applied the necessary mitigations server-side.

That doesn’t remove the need for your organization to verify the impact for your specific configuration. Some environments may require additional steps, depending on how your tenant and services are set up.

Practically, you can think about:

  • Checking which of the named Microsoft services are active in your environment
  • Confirming internally that patch status and mitigations match the announcement
  • Giving extra attention to identity and management components, such as Entra ID
  • Reviewing logging and detection posture for high-risk components

If you’ve also recently been dealing with vulnerabilities in identity or governance, it helps to keep your testing and rollout processes sharp.

Recent context: Copilot and ShieldBreak

This patch round isn’t coming out of nowhere. Microsoft previously noted that other updates were also underway or had recently been applied.

Copilot: command injection fixed earlier

According to Microsoft, a high-severity command injection vulnerability in Copilot was addressed earlier this week. The bug could be exploited remotely for information disclosure. This matters because it shows Microsoft continues to work on security issues in AI and assistant environments.

ShieldBreak (Defender) and the role of zero-days

Microsoft also said it is working on patches for ShieldBreak, a zero-day Defender exploit that was rolled out on Patch Tuesday in August 2026. Microsoft links the attack to CVE-2026-69414 with a CVSS score of 7.8. Microsoft’s statement emphasizes that this involves an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender.

If you want to put developments like this into perspective, it can help to take earlier reporting about direct patching and exploit expectations into account when setting priorities.

Related reading: TrueConf vulnerabilities: patching immediately shows how quickly things in the wild can escalate when patching doesn’t happen on time.

Where should you stay especially alert within the 22 security patches?

Even though Microsoft says many mitigations are already applied server-side, it’s still wise to remain alert to the types of vulnerabilities that show up in the list. These are mainly:

  • Elevation of Privilege in core cloud management and identity components
  • Remote Code Execution in specific Azure components and Entra ID
  • High-severity issues in data platforms and integration components

In other words: if your organization heavily relies on Azure services, Microsoft Fabric or Entra ID, this is exactly the kind of patch cycle your risk analysis and monitoring should be aligned with.

And if you also use GitLab, recent reports about critical vulnerabilities that were exploited shortly after public disclosure can be a signal for your policies around speed and validation. For example, consider the earlier reporting on this site if you want to dig deeper into exploitation trends (without having to guess which CVEs are relevant to you).

Checklist: make patch information usable

Not every organization has the same level of maturity in its patch cycle. That’s why it helps to translate the announcement into a small, repeatable approach.

1) Map CVEs to the services you use

Start by listing which Azure services and identity components you’re actually running. Based on that, you can determine which of the 22 security patches are most relevant.

2) Verify mitigations and exceptions

Because Microsoft applies server-side mitigations in many cases, it’s worth confirming internally that your setup has no deviations. Think of special network configurations or hardening that require extra testing.

3) Pay attention to identity components

Entra ID is explicitly mentioned with a CVSS 10/10 RCE-related vulnerability. Identity is often a key component, so it’s a good idea to sharpen detection and incident response.

4) Include recent Copilot/Defender context

By linking the recent Copilot fixes and the ShieldBreak developments, you can better support your security roadmap. It’s not just about “patching,” but also about tracking threat scenarios.

Conclusion

With the rollout of 22 security patches, Microsoft addresses multiple serious vulnerabilities in, among other areas, Azure, Entra ID and Exchange Online. The patch round includes several problems with CVSS 10/10, including EoP issues and RCE vulnerabilities.

Because Microsoft indicates that for many defects there’s no customer action required, the first step is mainly: determine which services you use and verify internally that mitigations and configurations are correct. By translating the information this way, you make Microsoft’s patch details immediately practical for your own security.

Source: https://www.securityweek.com/microsoft-rolls-out-22-fresh-security-patches/