Microsoft Patches Exploited Entra ID Zero-Day and 21 Other Flaws
Microsoft on Thursday released 22 security updates addressing severe vulnerabilities across its product portfolio, headlined by an actively exploited zero-day in Entra ID. Tracked as CVE-2026-69836, the flaw enabled remote code execution and was discovered internally by Microsoft. The company mitigated the issue on the server side, so no customer action is required, though it has not disclosed details about the in-the-wild attacks targeting this vulnerability. Organizations relying on Entra ID for identity and access management should verify tenant activity logs for any signs of compromise, and admins can run a quick privacy checkup to ensure session and authentication baselines remain intact.
Beyond the Entra ID zero-day, several flaws were assigned the maximum CVSS score of 10/10, including elevation-of-privilege bugs in Azure SQL Database (CVE-2026-69502), Azure Arc (CVE-2026-69555 and CVE-2026-65816), and Exchange Online (CVE-2026-65801), as well as a remote code execution issue in Azure Managed Instance for Apache Cassandra (CVE-2026-65770). Microsoft also resolved seven additional critical elevation-of-privilege vulnerabilities spanning Azure SQL Database, Microsoft Fabric, Entra ID, Azure Logic Apps, and Azure Data Factory. High-severity patches covered Azure Virtual Machines, Microsoft Partner Center, Azure Stack HCI, Azure Data Manager for Energy, Copilot in Azure, and Windows Remote Help Defense. The breadth of these cloud-focused fixes makes it worthwhile to confirm your external attack surface with a port scanner to identify any Azure-exposed services that may need tightening.
Earlier in the week, Microsoft separately fixed a high-severity command injection bug in Copilot, CVE-2026-24301, that could be exploited for remote information disclosure. The company also confirmed it is finalizing a patch for "ShieldBreak," a Defender zero-day that security researcher Nightmare Eclipse (aka Chaotic Eclipse) publicly disclosed during the August 2026 Patch Tuesday. The underlying flaw, CVE-2026-69414, carries a CVSS score of 7.8 and allows local elevation of privilege within the Microsoft Malware Protection Engine. Microsoft stated it is "working to provide a high-quality security update" and advised users to monitor Defender telemetry for suspicious behavior until the fix ships.
With 22 patches closed in a single update cycle and at least one known-exploited issue among them, defenders should review tenant audit logs, rotate any credentials that may have traversed Entra ID-authenticated services, and require phishing-resistant authentication on privileged accounts. Run a password checker on stored credentials and confirm that any hybrid or federated identities are protected by strong primary factors before the next Patch Tuesday arrives.