{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/microsoft-entra-provisioning-service/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:microsoft:edge_chromium:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-50481"},{"cvss":9.6,"id":"CVE-2026-56161"},{"cvss":10,"id":"CVE-2026-63508"},{"cvss":8.8,"id":"CVE-2026-62870"},{"cvss":7.4,"id":"CVE-2026-65802"},{"cvss":7.7,"id":"CVE-2026-66310"},{"cvss":7.1,"id":"CVE-2026-66322"},{"cvss":7.4,"id":"CVE-2026-66321"},{"cvss":8.1,"id":"CVE-2026-66318"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=C70098EC-8455-5303-80B5-BD82E10260AE\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Windows","Microsoft Entra ID","curl","Azure Kubernetes Service","Azure Storage","GitHub","Elastic Stack","Azure Kubernetes Service (AKS)","Microsoft 365","SOHO routers","Azure Cosmos DB","Android","Windows Subsystem for Linux","PowerShell","Microsoft 365 Apps for Enterprise","Microsoft Excel 2016 (\u003c 16.0.5561.1001)","Microsoft Office 2019","Microsoft Office LTSC 2021","Microsoft Office LTSC 2024","Roblox","Discord","Minecraft","Xbox Game Bar",".NET Framework (\u003c= 4.8.1)",".NET Runtime (8.0.0 - 8.0.28, 9.0.0 - 9.0.17, 10.0.0 - 10.0.9)","Visual Studio 2022 (\u003c= 17.14)","Visual Studio 2026 (\u003c= 18.7)","Microsoft Edge (Android) (\u003c 151.0.4129.59)","Microsoft Edge for Android (\u003c 151.0.4129.59)","Microsoft Edge (Chromium-based) (\u003c 151.0.4129.59)","Edge","Excel 2016","Office 2019","Office 2021","Office 2024","Microsoft 365 Apps Enterprise","SharePoint Server","Internet Information Services","Azure Active Directory","Azure Service Bus","Azure Logic Apps","Microsoft Entra Provisioning Service","Power Apps","Azure SRE Agent","Microsoft 365 Admin Center","Microsoft Teams","Microsoft Planetary Computer Pro (GeoCatalog)","Azure Confidential Ledger","SharePoint Online","Application Insights Profiler","Azure SQL Managed Instance","Microsoft Purview eDiscovery"],"_cs_severities":["high"],"_cs_tags":["roundup"],"_cs_type":"threat","_cs_vendors":["Microsoft","Elastic","Google","GitHub","Roblox","Discord","Mojang"],"content_html":"\u003cp\u003eThis roundup covers 15 Microsoft security vulnerabilities. None are reported as actively exploited at the time of release. The issues affect Application Insights Profiler, Azure Active Directory, Azure Confidential Ledger, Azure Logic Apps, Azure SQL Managed Instance, Azure SRE Agent, Azure Service Bus, Microsoft 365 Admin Center, Microsoft Entra Provisioning Service, Microsoft Planetary Computer Pro, Microsoft Teams, Power Apps, SharePoint Online.\u003c/p\u003e\n\u003ch2 id=\"summary\"\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\t\u003cthead\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003cth\u003eCVE\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eCVSS\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eProduct\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eSummary\u003c/th\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/thead\u003e\n\t\u003ctbody\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-50481\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e9.9\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAzure Active Directory\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-50481 is a critical vulnerability in Microsoft Azure Active Directory involving the modification of assumed-immutable data (MAID). An authorized attacker can exploit this flaw to escalate privileges within the environment over a network, potentially leading to unauthorized administrative access.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-50515\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e0.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAzure Service Bus\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-50515 is a critical deserialization of untrusted data vulnerability in Azure Service Bus that permits an authenticated attacker with low privileges to achieve remote code execution. Detection efforts should focus on monitoring anomalous serialized data payloads sent to service bus endpoints and unexpected process execution spawned by the Azure Service Bus service account.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-56161\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e9.6\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAzure Logic Apps\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-56161 describes an improper access control vulnerability in Microsoft Azure Logic Apps. An authenticated attacker can exploit this vulnerability to disclose sensitive information over a network. The vulnerability carries a CVSS 3.1 base score of 9.6, indicating a critical risk.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-59115\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e0.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eMicrosoft Entra Provisioning Service\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-59115 is a critical path traversal vulnerability in the Microsoft Entra Provisioning Service (SyncFabric). An authorized attacker can leverage this vulnerability by using a specific input string ('.../...//') to elevate their privileges over a network. The vulnerability has a CVSS base score of 9.9, indicating a significant risk to the integrity, confidentiality, and availability of the affected cloud service.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-59118\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e0.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003ePower Apps\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-59118 is an improper authorization vulnerability in Microsoft Power Apps that allows an unauthorized attacker to perform a privilege escalation over a network. The vulnerability carries a CVSS 3.1 base score of 9.3, indicating a critical severity impact on confidentiality and integrity, necessitating restricted access controls within the affected cloud service.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-62830\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e0.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAzure SRE Agent\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eA vulnerability in the Azure SRE Agent stemming from missing authorization (CWE-862) allows an already authorized network attacker to perform privilege escalation. The vulnerability is rated critical with a CVSS 3.1 score of 9.9, as it enables full scope impact across confidentiality, integrity, and availability within the cloud environment.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-62873\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e0.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eMicrosoft 365 Admin Center\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eThe Microsoft 365 Admin Center is vulnerable to an improper verification of cryptographic signature vulnerability (CWE-347). This flaw allows a remote, unauthorized attacker to elevate their privileges over a network, potentially leading to full compromise of confidentiality, integrity, and availability.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-62896\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e0.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eMicrosoft Teams\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eMicrosoft Teams contains an improper authentication vulnerability that allows an authenticated attacker to perform privilege escalation over a network. This flaw represents a critical security risk due to the potential for unauthorized access elevation within the application environment.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-63508\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e0.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eMicrosoft Planetary Computer Pro (GeoCatalog)\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eMicrosoft Planetary Computer Pro (GeoCatalog) contains a vulnerability due to missing authentication for a critical function. This allows an unauthorized attacker to perform privilege escalation over a network. The vulnerability is classified as critical and has a CVSS base score of 10.0.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-65667\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e0.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eMicrosoft Teams\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-65667 is a critical security vulnerability in Microsoft Teams involving missing authorization (CWE-862). This flaw allows a remote, unauthenticated attacker to elevate privileges over a network, potentially leading to unauthorized access to sensitive information and system integrity compromises.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-68823\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e0.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAzure Confidential Ledger\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-68823 involves an exposed dangerous method or function in the Azure Confidential Ledger service, which allows an authorized attacker to achieve remote code execution over a network. The vulnerability is classified as CWE-749 and carries a critical CVSS base score of 9.1.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-70332\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e0.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eSharePoint Online\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-70332 is a Server-Side Request Forgery (SSRF) vulnerability in Microsoft SharePoint Online. An unauthenticated attacker can exploit this flaw to perform spoofing over a network, potentially leading to unauthorized information disclosure, interaction with internal services, or further lateral movement within the cloud environment.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-49163\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e0.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eApplication Insights Profiler\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eApplication Insights Profiler is vulnerable to a path traversal flaw (CWE-22) that allows an authorized attacker to elevate their privileges over a network. This vulnerability indicates improper limitation of a pathname to a restricted directory.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-62836\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e0.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eAzure SQL Managed Instance\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-62836 identifies a vulnerability in Azure SQL Managed Instance due to improper restriction of communication channels to intended endpoints. This flaw allows an unauthenticated, remote attacker to escalate privileges over a network connection by exploiting the misconfigured communication path.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-62918\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e0.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eMicrosoft Teams\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-62918 is a vulnerability in Microsoft Teams involving improper verification of cryptographic signatures. This flaw allows an unauthorized remote attacker to perform spoofing attacks over a network, potentially leading to unauthorized data manipulation or masquerading within the platform.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2 id=\"cve-2026-50481\"\u003eCVE-2026-50481\u003c/h2\u003e\n\u003cp\u003eCVE-2026-50481 is a critical vulnerability in Microsoft Azure Active Directory involving the modification of assumed-immutable data (MAID). An authorized attacker can exploit this flaw to escalate privileges within the environment over a network, potentially leading to unauthorized administrative access.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAzure Active Directory\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-50481\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-50481\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-50515\"\u003eCVE-2026-50515\u003c/h2\u003e\n\u003cp\u003eCVE-2026-50515 is a critical deserialization of untrusted data vulnerability in Azure Service Bus that permits an authenticated attacker with low privileges to achieve remote code execution. Detection efforts should focus on monitoring anomalous serialized data payloads sent to service bus endpoints and unexpected process execution spawned by the Azure Service Bus service account.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAzure Service Bus\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-50515\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-50515\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-56161\"\u003eCVE-2026-56161\u003c/h2\u003e\n\u003cp\u003eCVE-2026-56161 describes an improper access control vulnerability in Microsoft Azure Logic Apps. An authenticated attacker can exploit this vulnerability to disclose sensitive information over a network. The vulnerability carries a CVSS 3.1 base score of 9.6, indicating a critical risk.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAzure Logic Apps\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-56161\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-56161\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-59115\"\u003eCVE-2026-59115\u003c/h2\u003e\n\u003cp\u003eCVE-2026-59115 is a critical path traversal vulnerability in the Microsoft Entra Provisioning Service (SyncFabric). An authorized attacker can leverage this vulnerability by using a specific input string ('.../...//') to elevate their privileges over a network. The vulnerability has a CVSS base score of 9.9, indicating a significant risk to the integrity, confidentiality, and availability of the affected cloud service.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMicrosoft Entra Provisioning Service\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-59115\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-59115\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-59118\"\u003eCVE-2026-59118\u003c/h2\u003e\n\u003cp\u003eCVE-2026-59118 is an improper authorization vulnerability in Microsoft Power Apps that allows an unauthorized attacker to perform a privilege escalation over a network. The vulnerability carries a CVSS 3.1 base score of 9.3, indicating a critical severity impact on confidentiality and integrity, necessitating restricted access controls within the affected cloud service.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePower Apps\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-59118\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-59118\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-62830\"\u003eCVE-2026-62830\u003c/h2\u003e\n\u003cp\u003eA vulnerability in the Azure SRE Agent stemming from missing authorization (CWE-862) allows an already authorized network attacker to perform privilege escalation. The vulnerability is rated critical with a CVSS 3.1 score of 9.9, as it enables full scope impact across confidentiality, integrity, and availability within the cloud environment.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAzure SRE Agent\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-62830\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-62830\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-62873\"\u003eCVE-2026-62873\u003c/h2\u003e\n\u003cp\u003eThe Microsoft 365 Admin Center is vulnerable to an improper verification of cryptographic signature vulnerability (CWE-347). This flaw allows a remote, unauthorized attacker to elevate their privileges over a network, potentially leading to full compromise of confidentiality, integrity, and availability.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMicrosoft 365 Admin Center\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-62873\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-62873\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-62896\"\u003eCVE-2026-62896\u003c/h2\u003e\n\u003cp\u003eMicrosoft Teams contains an improper authentication vulnerability that allows an authenticated attacker to perform privilege escalation over a network. This flaw represents a critical security risk due to the potential for unauthorized access elevation within the application environment.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMicrosoft Teams\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-62896\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-62896\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-63508\"\u003eCVE-2026-63508\u003c/h2\u003e\n\u003cp\u003eMicrosoft Planetary Computer Pro (GeoCatalog) contains a vulnerability due to missing authentication for a critical function. This allows an unauthorized attacker to perform privilege escalation over a network. The vulnerability is classified as critical and has a CVSS base score of 10.0.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMicrosoft Planetary Computer Pro (GeoCatalog)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-63508\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-63508\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-65667\"\u003eCVE-2026-65667\u003c/h2\u003e\n\u003cp\u003eCVE-2026-65667 is a critical security vulnerability in Microsoft Teams involving missing authorization (CWE-862). This flaw allows a remote, unauthenticated attacker to elevate privileges over a network, potentially leading to unauthorized access to sensitive information and system integrity compromises.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMicrosoft Teams\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-65667\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-65667\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-68823\"\u003eCVE-2026-68823\u003c/h2\u003e\n\u003cp\u003eCVE-2026-68823 involves an exposed dangerous method or function in the Azure Confidential Ledger service, which allows an authorized attacker to achieve remote code execution over a network. The vulnerability is classified as CWE-749 and carries a critical CVSS base score of 9.1.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAzure Confidential Ledger\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-68823\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-68823\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-70332\"\u003eCVE-2026-70332\u003c/h2\u003e\n\u003cp\u003eCVE-2026-70332 is a Server-Side Request Forgery (SSRF) vulnerability in Microsoft SharePoint Online. An unauthenticated attacker can exploit this flaw to perform spoofing over a network, potentially leading to unauthorized information disclosure, interaction with internal services, or further lateral movement within the cloud environment.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eSharePoint Online\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-70332\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-70332\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-49163\"\u003eCVE-2026-49163\u003c/h2\u003e\n\u003cp\u003eApplication Insights Profiler is vulnerable to a path traversal flaw (CWE-22) that allows an authorized attacker to elevate their privileges over a network. This vulnerability indicates improper limitation of a pathname to a restricted directory.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eApplication Insights Profiler\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-49163\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-49163\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-62836\"\u003eCVE-2026-62836\u003c/h2\u003e\n\u003cp\u003eCVE-2026-62836 identifies a vulnerability in Azure SQL Managed Instance due to improper restriction of communication channels to intended endpoints. This flaw allows an unauthenticated, remote attacker to escalate privileges over a network connection by exploiting the misconfigured communication path.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAzure SQL Managed Instance\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-62836\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-62836\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-62918\"\u003eCVE-2026-62918\u003c/h2\u003e\n\u003cp\u003eCVE-2026-62918 is a vulnerability in Microsoft Teams involving improper verification of cryptographic signatures. This flaw allows an unauthorized remote attacker to perform spoofing attacks over a network, potentially leading to unauthorized data manipulation or masquerading within the platform.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMicrosoft Teams\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-62918\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-62918\u003c/a\u003e\u003c/p\u003e\n","date_modified":"2026-08-07T01:30:25Z","date_published":"2026-08-01T01:41:40Z","id":"https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/","summary":"Roundup of Microsoft security advisories published in August 2026.","title":"Microsoft Security Updates — August 2026","url":"https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/"}],"language":"en","title":"CraftedSignal Threat Feed - Microsoft Entra Provisioning Service","version":"https://jsonfeed.org/version/1.1"}