Curated read

· SecurityWeek

Microsoft Rolls Out 22 Fresh Security Patches

Most of the fixes resolve code execution, privilege escalation, and information disclosure vulnerabilities. The post Microsoft Rolls Out 22 Fresh Security Patches appeared first on SecurityWeek.

From our desk

Microsoft on Thursday announced the rollout of 22 new security updates that resolve severe vulnerabilities across multiple products.

Most of the patches address critical and high-severity flaws in Microsoft Azure, Entra ID, Exchange, Fabric, and Partner Center products.

The most severe of these include elevation of privilege (EoP) bugs in Azure SQL Database (CVE-2026-69502), Azure Arc (CVE-2026-69555 and CVE-2026-65816), and Exchange Online (CVE-2026-65801), and remote code execution (RCE) flaws in Azure Managed Instance for Apache Cassandra (CVE-2026-65770), and Entra ID (CVE-2026-69836), all with a CVSS score of 10/10.

Seven other critical EoP issues were resolved: CVE-2026-68782 (Azure SQL Database), CVE-2026-63509 (Microsoft Fabric), CVE-2026-69851 (Entra ID), CVE-2026-68789 (Azure SQL Database), CVE-2026-69400 (Azure Logic Apps), CVE-2026-62834 (Azure Data Factor), and CVE-2026-66309 (Azure SQL Database).

Additionally, Microsoft patched high-severity vulnerabilities in Azure Virtual Machines, Microsoft Partner Center, Azure Data Factory, Azure Stack HCI, Azure Data Manager for Energy, Copilot in Azure, and Windows Remote Help Defense.

No customer action is required for the majority of these security defects, as Microsoft has deployed the mitigations on the server side.Advertisement. Scroll to continue reading.

Earlier this week, Microsoft fixed a high-severity command injection bug in Copilot that could be exploited remotely for information disclosure (CVE-2026-24301).

Last week, the company announced that it was working on patches for ShieldBreak, a zero-day Defender exploit dropped on August 2026 Patch Tuesday by security researcher Nightmare Eclipse (also known as Chaotic Eclipse).

The company assesses that the vulnerability ShieldBreak targets is a high-severity bug, now tracked as CVE-2026-69414 (CVSS score of 7.8).

“Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as ‘ShieldBreak’. We are working to provide a high-quality security update that addresses this vulnerability,” the company said.

Related: CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

Related: Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler

Related: Critical GitLab Flaw Exploited Shortly After Disclosure

Related: CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities

Written By Ionut Arghire

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

More from Ionut Arghire

Exploitation Expected for Critical Authentication Bypass Patched in Citrix NetScaler Critical GitLab Flaw Exploited Shortly After Disclosure Prevalent AI Raises $22 Million to Expand Data Fabric Platform US Charges 17 Iranian Hackers, Offers $10 Million Rewards for 5 of Them CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities 943 Patches Rolled Out With Oracle’s August 2026 Security Update Chrome, Firefox Updates Patch Dozens of Vulnerabilities Xpander Raises $7.5 Million for AI Management and Governance

Latest News

Contractors’ CMMC Confidence Rises as Ability to Prove It Falls Behind CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities Hackers Target Zimbra Servers in Active Exploitation Campaign Surveillance – Everything You Wanted to Know, But Were Afraid to Ask Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities MLflow Vulnerability Exploited for Cloud Credential Theft Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities

Cloud SecurityVulnerabilitiesMicrosoftpatchesvulnerability

Primary source and any official IoCs, figures, and legal text live with the publisher. Use the button below to read their version in full; our page is an editorial layer for the Senthorion community.

Microsoft Rolls Out 22 Fresh Security Patches | Senthorion blog