Microsoft Security Updates - September 2026
Roundup of Microsoft security advisories published in September 2026.
CVE search metadata
CVE search record: CVE-2026-62916. Severity: critical. CVSS: 9.1. KEV: no. Product: Entra ID. Brief: Microsoft Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-microsoft-security-updates/
CVE search record: CVE-2026-70352. Severity: critical. CVSS: 10.0. KEV: no. Product: Azure AI Language. Brief: Microsoft Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-microsoft-security-updates/
CVE search record: CVE-2026-80098. Severity: critical. CVSS: 9.3. KEV: no. Product: Copilot Studio. Brief: Microsoft Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-microsoft-security-updates/
CVE search record: CVE-2026-83711. Severity: critical. CVSS: 10.0. KEV: no. Product: Azure Active Directory B2C. Brief: Microsoft Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-microsoft-security-updates/
CVE search record: CVE-2026-62906. Severity: high. CVSS: 7.4. KEV: no. Product: Discovery Studio. Brief: Microsoft Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-microsoft-security-updates/
CVE search record: CVE-2026-65818. Severity: high. CVSS: 8.5. KEV: no. Brief: Microsoft Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-microsoft-security-updates/
What's new
This roundup covers 6 Microsoft security vulnerabilities. CVSS base scores range from 7.4 to 10.0. None are reported as actively exploited at the time of release. The issues affect Azure AI Language, Azure Active Directory B2C, Copilot Studio, Discovery Studio, Entra ID, Power Automate.
Summary
| CVE | Product | Severity | CVSS | EPSS | KEV | Source |
|---|---|---|---|---|---|---|
| CVE-2026-62916 | Entra ID | Critical | 9.1 | no | NVD (authoritative) | |
| CVE-2026-70352 | Azure AI Language | Critical | 10.0 | no | NVD (authoritative) | |
| CVE-2026-80098 | Copilot Studio | Critical | 9.3 | no | NVD (authoritative) | |
| CVE-2026-83711 | Azure Active Directory B2C | Critical | 10.0 | no | NVD (authoritative) | |
| CVE-2026-62906 | Discovery Studio | High | 7.4 | no | NVD (authoritative) | |
| CVE-2026-65818 | Power Automate | no | NVD (authoritative) |
CVE-2026-62916
CVE-2026-62916 is an authentication bypass vulnerability in Microsoft Entra ID arising from the use of an alternate path or channel. This vulnerability permits an unauthorized remote attacker to perform privilege escalation within the identity management environment.
Affected products:
- Entra ID
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62916
CVE-2026-70352
CVE-2026-70352 describes a critical vulnerability in Microsoft's Azure AI Language service where a missing authentication control on a critical function allows an unauthorized remote attacker to perform privilege escalation. The vulnerability carries a CVSS base score of 10.0, indicating high severity and potential for exploitation over a network.
Affected products:
- Azure AI Language
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70352
CVE-2026-80098
CVE-2026-80098 is a vulnerability in Microsoft Copilot Studio involving improper verification of cryptographic signatures. This flaw allows an unauthorized attacker to perform a privilege escalation attack over a network, presenting a significant security risk given its high CVSS base score.
Affected products:
- Copilot Studio
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-80098
CVE-2026-83711
An authorization bypass vulnerability exists in Microsoft Azure Active Directory B2C due to improper handling of user-controlled keys. An unauthenticated attacker can exploit this flaw over the network to elevate privileges, leading to a critical security impact.
Affected products:
- Azure Active Directory B2C
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83711
CVE-2026-62906
CVE-2026-62906 describes an improper neutralization of special elements in data query logic within Microsoft Discovery Studio. This vulnerability allows an unauthorized remote attacker to perform unauthorized data disclosure over a network, potentially exposing sensitive information due to flawed query handling.
Affected products:
- Discovery Studio
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62906
CVE-2026-65818
CVE-2026-65818 is a server-side request forgery (SSRF) vulnerability in Microsoft Power Automate that enables an authorized attacker to perform privilege escalation over a network.
Affected products:
- Power Automate