On September 3, 2026, Microsoft announced its early security update for September, addressing vulnerabilities in multiple cloud services. Notably, two vulnerabilities received a CVSS 3.1 severity score of 10.0, indicating critical risks that have been mitigated by Microsoft.
The vulnerabilities include CVE-2026-70352 in Azure AI Language and CVE-2026-83711 in Microsoft Azure Active Directory B2C, both allowing unauthorized attackers to escalate privileges over the network. Microsoft confirmed that all identified vulnerabilities have been fully mitigated, ensuring that users do not need to take additional protective measures.
With seven vulnerabilities related to privilege escalation and one to information disclosure, the update underscores the importance of ongoing security management in cloud services. No further timeline was disclosed at the time of publication.
Editor's Note
As cloud services continue to evolve, the security landscape remains a critical focus for enterprises. Microsoft's proactive approach in addressing high-severity vulnerabilities reflects the increasing need for robust security measures in cloud environments. Organizations must stay vigilant and prioritize timely updates to safeguard their systems against potential threats.
Leave a comment