VYPR
Vypr IntelligenceAI-generatedSep 3, 2026· 9 CVEs

Microsoft Azure & Windows: Nine Critical Vulns Disclosed, Enabling Privilege Escalation

Microsoft disclosed nine critical and high-severity vulnerabilities across Azure and Windows services on Sept 3, 2026, enabling privilege escalation and other attacks.

Key findings

  • Nine vulnerabilities disclosed by Microsoft between Sept 2-3, 2026, affecting Azure and Windows services.
  • Multiple critical vulnerabilities allow for privilege escalation via authorization/authentication bypasses.
  • Affected services include Azure AD B2C, Copilot Studio, Azure AI Language, and Entra ID.
  • High-severity flaws include SSRF, spoofing, and information disclosure risks.
  • Windows ML CLI vulnerable due to unauthenticated localhost API and wildcard origins.
  • Patches are available; prompt application is crucial for mitigation.

On September 3, 2026, Microsoft disclosed a batch of nine vulnerabilities affecting various Azure and Windows services. The vulnerabilities, disclosed between September 2 and September 3, 2026, predominantly carry critical or high severity ratings, with several allowing for privilege escalation over a network. This coordinated disclosure event highlights significant security weaknesses across Microsoft's cloud and AI offerings.

Several critical vulnerabilities center on authorization and authentication bypasses. CVE-2026-83711, a critical authorization bypass in Microsoft Azure Active Directory B2C, allows attackers to elevate privileges. Similarly, CVE-2026-70352, a critical flaw in Azure AI Language, involves a missing authentication for a critical function, also enabling privilege escalation. Another critical vulnerability, CVE-2026-62916, affects Microsoft Entra ID with an authentication bypass, permitting unauthorized privilege elevation. CVE-2026-80098, a critical vulnerability in Copilot Studio, stems from improper verification of cryptographic signatures, leading to privilege escalation.

High-severity flaws also present significant risks. CVE-2026-70178, a high-severity vulnerability in Microsoft Fabric, involves missing authorization that could lead to privilege escalation. Azure Cosmos DB is affected by CVE-2026-69857, a high-severity authorization bypass allowing for spoofing. Power Automate contains CVE-2026-65818, a high-severity server-side request forgery (SSRF) vulnerability that could enable privilege escalation. Additionally, CVE-2026-62906, a high-severity issue in Microsoft Discovery Studio, involves improper neutralization of special elements in data query logic, potentially leading to information disclosure. Finally, CVE-2026-84452, a high-severity vulnerability affecting the Windows ML CLI prior to version 0.4.0, exposes WinML CLI commands through a localhost HTTP API without authentication and uses a wildcard for allow_origins.

The impact of these vulnerabilities is substantial, with many allowing for unauthorized privilege escalation, a common precursor to more significant system compromise. The disclosure of multiple critical flaws across core Azure services and AI platforms underscores the need for immediate attention from administrators and users. The affected services include Azure Active Directory B2C, Copilot Studio, Azure AI Language, Microsoft Fabric, Azure Cosmos DB, Power Automate, Microsoft Entra ID, Microsoft Discovery Studio, and Windows ML CLI.

Microsoft has released patches and updates to address these vulnerabilities. Users are strongly advised to consult Microsoft's official security advisories for detailed information on affected versions and the specific patches required for each product. Prompt application of these updates is crucial to mitigate the risk of exploitation.

This batch of vulnerabilities serves as a critical reminder for organizations utilizing Microsoft's cloud and AI services to maintain a robust patch management strategy. The interconnected nature of these services means that a compromise in one area can have cascading effects. Continuous monitoring and timely updates are essential to safeguard sensitive data and maintain the integrity of cloud environments. The coordinated disclosure suggests a proactive approach by Microsoft in addressing these issues, but user diligence in applying fixes remains paramount.

AI-written article. Grounded in 9 CVE records listed below.