Microsoft: Seven Vulnerabilities Including Five Critical Flaws Disclosed Together
Microsoft addresses a batch of seven vulnerabilities, including five critical flaws, impacting services like Azure, Partner Center, and Bookings, disclosed simultaneously on October 8, 2026.

Key findings
- Microsoft disclosed seven vulnerabilities on October 8, 2026, including five critical and two high-severity flaws.
- Vulnerabilities affect a range of Microsoft products including Partner Center, Bookings, Dataverse, Azure Event Grid, Azure API Center, Azure App Service, and Azure SRE Agent.
- Impacts include privilege escalation, authorization bypass, remote code execution, and sensitive information disclosure.
- All disclosed vulnerabilities were patched by Microsoft on the same day as disclosure.
- Users are urged to apply updates promptly to mitigate risks associated with these critical and high-severity flaws.
On October 8, 2026, Microsoft disclosed a batch of seven vulnerabilities, including several critical severity flaws, affecting various Microsoft products and services. The disclosures occurred simultaneously, indicating a coordinated release of security information. These vulnerabilities span across different components, including Microsoft Partner Center, Microsoft Bookings, Microsoft Dataverse, Azure Event Grid, Azure API Center, Azure App Service, and Azure SRE Agent. The collective impact ranges from privilege escalation and authorization bypass to information disclosure and remote code execution, posing significant risks to organizations utilizing these Microsoft services.
Several critical vulnerabilities were detailed in the disclosure:
- CVE-2026-96207, a critical flaw in Microsoft Partner Center, allows an attacker to elevate privileges due to improper certificate validation.
- CVE-2026-94510, also critical, affects Microsoft Bookings and enables privilege escalation through a user-controlled key vulnerability.
- CVE-2026-88131, a critical deserialization vulnerability in Microsoft Dataverse, could permit an attacker to execute code remotely.
- CVE-2026-77900, a critical issue in Azure App Service, involves missing authentication for a critical function, potentially leading to code execution.
- CVE-2026-69435, a critical vulnerability in Azure SRE Agent, allows for privilege escalation due to missing authorization.
In addition to the critical flaws, two high-severity vulnerabilities were also part of this batch:
- CVE-2026-83947, a high-severity flaw in Azure Event Grid, permits spoofing due to missing authorization.
- CVE-2026-83943, a high-severity vulnerability in Azure API Center, exposes sensitive information to unauthorized actors.
The vulnerabilities were disclosed on the same day, October 8, 2026, with no significant time span between them, suggesting a unified patching or disclosure strategy by Microsoft. The affected services and products highlight the breadth of potential impact across Microsoft's ecosystem, from partner management to cloud-native application development and data management.
Microsoft has released patches and security updates to address these vulnerabilities. Users are strongly advised to consult the official Microsoft security advisories for each specific CVE to understand the affected versions and apply the necessary updates promptly. Prompt patching is crucial to mitigate the risk of exploitation, particularly for the critical vulnerabilities that could lead to remote code execution or significant privilege escalation.
This coordinated disclosure event underscores the importance of continuous monitoring and timely patching of Microsoft products and services. Organizations relying on these platforms should prioritize the review and application of security updates to protect their environments from potential threats exploiting these newly revealed weaknesses. The range of affected services indicates a need for a comprehensive security approach across the entire Microsoft stack.