VYPR
patchPublished Aug 7, 2026· Updated Aug 10, 2026· 1 source

Microsoft: 17 Vulnerabilities Patched, Including Four Critical Flaws on August 7

Key findings • Microsoft patched 17 vulnerabilities on August 7, 2026, across its product suite. • Four vulnerabilities received a maximum CVSSv3 score of 10.0, including critical flaws in Te…

Key findings

  • Microsoft patched 17 vulnerabilities on August 7, 2026, across its product suite.
  • Four vulnerabilities received a maximum CVSSv3 score of 10.0, including critical flaws in Teams, Azure SQL Database, and Planetary Computer Pro.
  • Vulnerabilities span across Azure, Microsoft Teams, SharePoint, and other key services, with impacts ranging from privilege escalation to code execution.
  • The batch includes critical flaws such as XSS, missing authorization/authentication, and improper signature verification.
  • SecurityWeek reported on the critical severity of CVE-2026-63508, CVE-2026-56162, and CVE-2026-65667.
  • All disclosed vulnerabilities have been patched by Microsoft.

On August 7, 2026, Microsoft released security updates addressing a significant batch of 17 vulnerabilities disclosed on the same day. The vulnerabilities span a wide range of Microsoft products and services, including Azure, Microsoft Teams, Microsoft 365 Admin Center, and SharePoint, with several rated as Critical severity. This coordinated disclosure event highlights ongoing security challenges across Microsoft's extensive ecosystem.

Several critical vulnerabilities were disclosed, with four receiving the maximum CVSSv3 score of 10.0. These include CVE-2026-65667 and CVE-2026-63508, both described as missing authorization or authentication flaws in Microsoft Teams and Microsoft Planetary Computer Pro, respectively, allowing for privilege escalation. Additionally, CVE-2026-56162 in Azure SQL Database and CVE-2026-65668 in Microsoft Purview eDiscovery also carry high severity ratings, with the former being an improper authentication issue and the latter an improper access control flaw, both leading to privilege escalation.

Other critical vulnerabilities include CVE-2026-70332, a cross-site scripting (XSS) flaw in Microsoft Office SharePoint, and CVE-2026-62896, an improper authentication vulnerability in Microsoft Teams, both allowing for spoofing and privilege escalation respectively. CVE-2026-62873 in the Microsoft 365 Admin Center involves improper verification of cryptographic signatures, enabling privilege escalation. Furthermore, CVE-2026-59115 in Microsoft Entra Provisioning Service and CVE-2026-50515 in Azure Service Bus present critical risks, with the former being an authorization bypass and the latter a deserialization of untrusted data vulnerability, both potentially leading to code execution or privilege escalation.

The batch also includes several high-severity vulnerabilities. CVE-2026-62918 in Microsoft Teams is an improper verification of cryptographic signature flaw. CVE-2026-62836 in Azure SQL Managed Instance involves improper restriction of communication channels, and CVE-2026-49163 in Application Insights Profiler is a path traversal vulnerability. These, along with other critical flaws like CVE-2026-62830 in Azure SRE Agent and CVE-2026-59118 in Microsoft Power Apps, underscore the breadth of security issues addressed.

According to SecurityWeek, three of the vulnerabilities, CVE-2026-63508, CVE-2026-56162, and CVE-2026-65667, were highlighted for their maximum severity rating of 10/10 and potential for exploitation over a network. These critical flaws in Planetary Computer Pro, Azure SQL Database, and Teams could lead to elevation of privilege. The report also mentions CVE-2026-50515 (RCE in Azure Service Bus) and CVE-2026-62830 (EoP in Azure SRE Agent) as significant risks.

Microsoft has released patches for all 17 vulnerabilities, urging users to update their systems promptly. The affected products include a wide array of services, emphasizing the need for continuous vigilance and timely patching across the Microsoft ecosystem. Users are advised to consult Microsoft's official security advisories for detailed information on affected versions and remediation steps.

This coordinated disclosure event serves as a reminder of the critical importance of regular security updates for Microsoft products. The sheer number and severity of the vulnerabilities patched in this single batch underscore the dynamic threat landscape and the ongoing efforts required to maintain a secure computing environment. Organizations relying on Microsoft services should prioritize applying these updates to mitigate potential risks.

Synthesized by Vypr AI