Skip to content
Threat Feed
high threat

Microsoft Security Updates - September 2026

Roundup of Microsoft security advisories published in September 2026.

CVE search metadata

CVE search record: CVE-2026-62916. Severity: critical. CVSS: 9.1. KEV: no. Product: Entra ID. Brief: Microsoft Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-microsoft-security-updates/

CVE search record: CVE-2026-70352. Severity: critical. CVSS: 10.0. KEV: no. Product: Azure AI Language. Brief: Microsoft Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-microsoft-security-updates/

CVE search record: CVE-2026-80098. Severity: critical. CVSS: 9.3. KEV: no. Product: Copilot Studio. Brief: Microsoft Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-microsoft-security-updates/

CVE search record: CVE-2026-83711. Severity: critical. CVSS: 10.0. KEV: no. Product: Azure Active Directory B2C. Brief: Microsoft Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-microsoft-security-updates/

CVE search record: CVE-2026-62906. Severity: high. CVSS: 7.4. KEV: no. Product: Discovery Studio. Brief: Microsoft Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-microsoft-security-updates/

CVE search record: CVE-2026-65818. Severity: high. CVSS: 8.5. KEV: no. Brief: Microsoft Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-microsoft-security-updates/

What's new

  • 1. added CVE-2026-62906, CVE-2026-65818 Sep 3, 23:25 via nvd, source
  • 2. added CVE-2026-70352, CVE-2026-80098, CVE-2026-83711 Sep 3, 23:24 via nvd, source, source

This roundup covers 6 Microsoft security vulnerabilities. CVSS base scores range from 7.4 to 10.0. None are reported as actively exploited at the time of release. The issues affect Azure AI Language, Azure Active Directory B2C, Copilot Studio, Discovery Studio, Entra ID, Power Automate.

Summary

CVEProductSeverityCVSSEPSSKEVSource
CVE-2026-62916Entra IDCritical9.1noNVD (authoritative)
CVE-2026-70352Azure AI LanguageCritical10.0noNVD (authoritative)
CVE-2026-80098Copilot StudioCritical9.3noNVD (authoritative)
CVE-2026-83711Azure Active Directory B2CCritical10.0noNVD (authoritative)
CVE-2026-62906Discovery StudioHigh7.4noNVD (authoritative)
CVE-2026-65818Power AutomatenoNVD (authoritative)

CVE-2026-62916

CVE-2026-62916 is an authentication bypass vulnerability in Microsoft Entra ID arising from the use of an alternate path or channel. This vulnerability permits an unauthorized remote attacker to perform privilege escalation within the identity management environment.

Affected products:

  • Entra ID

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62916

CVE-2026-70352

CVE-2026-70352 describes a critical vulnerability in Microsoft's Azure AI Language service where a missing authentication control on a critical function allows an unauthorized remote attacker to perform privilege escalation. The vulnerability carries a CVSS base score of 10.0, indicating high severity and potential for exploitation over a network.

Affected products:

  • Azure AI Language

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-70352

CVE-2026-80098

CVE-2026-80098 is a vulnerability in Microsoft Copilot Studio involving improper verification of cryptographic signatures. This flaw allows an unauthorized attacker to perform a privilege escalation attack over a network, presenting a significant security risk given its high CVSS base score.

Affected products:

  • Copilot Studio

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-80098

CVE-2026-83711

An authorization bypass vulnerability exists in Microsoft Azure Active Directory B2C due to improper handling of user-controlled keys. An unauthenticated attacker can exploit this flaw over the network to elevate privileges, leading to a critical security impact.

Affected products:

  • Azure Active Directory B2C

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-83711

CVE-2026-62906

CVE-2026-62906 describes an improper neutralization of special elements in data query logic within Microsoft Discovery Studio. This vulnerability allows an unauthorized remote attacker to perform unauthorized data disclosure over a network, potentially exposing sensitive information due to flawed query handling.

Affected products:

  • Discovery Studio

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-62906

CVE-2026-65818

CVE-2026-65818 is a server-side request forgery (SSRF) vulnerability in Microsoft Power Automate that enables an authorized attacker to perform privilege escalation over a network.

Affected products:

  • Power Automate

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-65818