Microsoft on Thursday announced the release of 22 new security updates that resolve serious vulnerabilities in multiple products, including a critical Entra ID zero-day used in attacks.
The Entra ID flaw used is tracked as CVE-2026-69836and may have been used for remote code execution (RCE). Microsoft discovered the problem internally and fixed it on the server side without requiring any action from customers.
The tech giant has not shared any information about the attacks involving the CVE-2026-69836 exploit.
Most of the other stickers addressing critical and critical gaps in Microsoft Azure, Entra ID, Exchange, Fabric and Partner Center products.
The most serious of these include elevation of privilege (EoP) vulnerabilities in Azure SQL Database (CVE-2026-69502), Azure Arc (CVE-2026-69555 and CVE-2026-65816), and Exchange Online (CVE-2026-65801), as well as an RCE flaw in Azure Managed Instance for Apache Cassandra (CVE-2026-65770), all with a CVSS result. 10/10.
Seven other critical EoP issues were resolved: CVE-2026-68782 (Azure SQL Database), CVE-2026-63509 (Microsoft Fabric), CVE-2026-69851 (Entra ID), CVE-2026-68789 (Azure SQL Database), CVE-2026-69400 (Azure Logic Apps), CVE-2026-62834 (Azure Data Factor) and CVE-2026-66309 (Azure SQL Database).
Additionally, Microsoft patched high-severity vulnerabilities in Azure Virtual Machines, Microsoft Partner Center, Azure Data Factory, Azure Stack HCI, Azure Data Manager for Energy, Copilot in Azure, and Windows Remote Help Defense.
Most of these security flaws do not require client-side action because Microsoft has implemented server-side mitigations.
Earlier this week, Microsoft fixed a high-severity command injection bug in Copilot that could be used remotely for information disclosure (CVE-2026-24301).
Last week, the company announced that it was working on patches for ShieldBreak, a Defender zero-day exploit dropped on August 2026 Patch Tuesday by security researcher Nightmare Eclipse (aka Chaotic Eclipse).
The company estimates that the vulnerability that ShieldBreak targets is a high-severity bug that is now being tracked as CVE-2026-69414 (CVSS score of 7.8).
“Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender, publicly referred to as ‘ShieldBreak’. We are working to provide a high-quality security update that addresses this vulnerability,” the company said.
* The title and body of the article have been updated to indicate that the Entra ID vulnerability was exploited
Related: CISA urges immediate remediation of exploited TrueConf vulnerabilities
Related: An exploit is expected for a critical authentication bypass fixed in Citrix NetScaler
Related: Critical GitLab flaw exploited shortly after disclosure
Related: CISA demands immediate patching of Microsoft, VMware, Apple exploited vulnerabilities