<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Microsoft Planetary Computer Pro (GeoCatalog) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/microsoft-planetary-computer-pro-geocatalog/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 01 Aug 2026 01:41:40 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/microsoft-planetary-computer-pro-geocatalog/feed.xml" rel="self" type="application/rss+xml"/><item><title>Microsoft Security Updates — August 2026</title><link>https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/</link><pubDate>Sat, 01 Aug 2026 01:41:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-microsoft-security-updates/</guid><description>Roundup of Microsoft security advisories published in August 2026.</description><content:encoded><![CDATA[<p>This roundup covers 15 Microsoft security vulnerabilities. None are reported as actively exploited at the time of release. The issues affect Application Insights Profiler, Azure Active Directory, Azure Confidential Ledger, Azure Logic Apps, Azure SQL Managed Instance, Azure SRE Agent, Azure Service Bus, Microsoft 365 Admin Center, Microsoft Entra Provisioning Service, Microsoft Planetary Computer Pro, Microsoft Teams, Power Apps, SharePoint Online.</p>
<h2 id="summary">Summary</h2>
<table>
	<thead>
			<tr>
					<th>CVE</th>
					<th>CVSS</th>
					<th>Product</th>
					<th>Summary</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td>CVE-2026-50481</td>
					<td>9.9</td>
					<td>Azure Active Directory</td>
					<td>CVE-2026-50481 is a critical vulnerability in Microsoft Azure Active Directory involving the modification of assumed-immutable data (MAID). An authorized attacker can exploit this flaw to escalate privileges within the environment over a network, potentially leading to unauthorized administrative access.</td>
			</tr>
			<tr>
					<td>CVE-2026-50515</td>
					<td>0.0</td>
					<td>Azure Service Bus</td>
					<td>CVE-2026-50515 is a critical deserialization of untrusted data vulnerability in Azure Service Bus that permits an authenticated attacker with low privileges to achieve remote code execution. Detection efforts should focus on monitoring anomalous serialized data payloads sent to service bus endpoints and unexpected process execution spawned by the Azure Service Bus service account.</td>
			</tr>
			<tr>
					<td>CVE-2026-56161</td>
					<td>9.6</td>
					<td>Azure Logic Apps</td>
					<td>CVE-2026-56161 describes an improper access control vulnerability in Microsoft Azure Logic Apps. An authenticated attacker can exploit this vulnerability to disclose sensitive information over a network. The vulnerability carries a CVSS 3.1 base score of 9.6, indicating a critical risk.</td>
			</tr>
			<tr>
					<td>CVE-2026-59115</td>
					<td>0.0</td>
					<td>Microsoft Entra Provisioning Service</td>
					<td>CVE-2026-59115 is a critical path traversal vulnerability in the Microsoft Entra Provisioning Service (SyncFabric). An authorized attacker can leverage this vulnerability by using a specific input string ('.../...//') to elevate their privileges over a network. The vulnerability has a CVSS base score of 9.9, indicating a significant risk to the integrity, confidentiality, and availability of the affected cloud service.</td>
			</tr>
			<tr>
					<td>CVE-2026-59118</td>
					<td>0.0</td>
					<td>Power Apps</td>
					<td>CVE-2026-59118 is an improper authorization vulnerability in Microsoft Power Apps that allows an unauthorized attacker to perform a privilege escalation over a network. The vulnerability carries a CVSS 3.1 base score of 9.3, indicating a critical severity impact on confidentiality and integrity, necessitating restricted access controls within the affected cloud service.</td>
			</tr>
			<tr>
					<td>CVE-2026-62830</td>
					<td>0.0</td>
					<td>Azure SRE Agent</td>
					<td>A vulnerability in the Azure SRE Agent stemming from missing authorization (CWE-862) allows an already authorized network attacker to perform privilege escalation. The vulnerability is rated critical with a CVSS 3.1 score of 9.9, as it enables full scope impact across confidentiality, integrity, and availability within the cloud environment.</td>
			</tr>
			<tr>
					<td>CVE-2026-62873</td>
					<td>0.0</td>
					<td>Microsoft 365 Admin Center</td>
					<td>The Microsoft 365 Admin Center is vulnerable to an improper verification of cryptographic signature vulnerability (CWE-347). This flaw allows a remote, unauthorized attacker to elevate their privileges over a network, potentially leading to full compromise of confidentiality, integrity, and availability.</td>
			</tr>
			<tr>
					<td>CVE-2026-62896</td>
					<td>0.0</td>
					<td>Microsoft Teams</td>
					<td>Microsoft Teams contains an improper authentication vulnerability that allows an authenticated attacker to perform privilege escalation over a network. This flaw represents a critical security risk due to the potential for unauthorized access elevation within the application environment.</td>
			</tr>
			<tr>
					<td>CVE-2026-63508</td>
					<td>0.0</td>
					<td>Microsoft Planetary Computer Pro (GeoCatalog)</td>
					<td>Microsoft Planetary Computer Pro (GeoCatalog) contains a vulnerability due to missing authentication for a critical function. This allows an unauthorized attacker to perform privilege escalation over a network. The vulnerability is classified as critical and has a CVSS base score of 10.0.</td>
			</tr>
			<tr>
					<td>CVE-2026-65667</td>
					<td>0.0</td>
					<td>Microsoft Teams</td>
					<td>CVE-2026-65667 is a critical security vulnerability in Microsoft Teams involving missing authorization (CWE-862). This flaw allows a remote, unauthenticated attacker to elevate privileges over a network, potentially leading to unauthorized access to sensitive information and system integrity compromises.</td>
			</tr>
			<tr>
					<td>CVE-2026-68823</td>
					<td>0.0</td>
					<td>Azure Confidential Ledger</td>
					<td>CVE-2026-68823 involves an exposed dangerous method or function in the Azure Confidential Ledger service, which allows an authorized attacker to achieve remote code execution over a network. The vulnerability is classified as CWE-749 and carries a critical CVSS base score of 9.1.</td>
			</tr>
			<tr>
					<td>CVE-2026-70332</td>
					<td>0.0</td>
					<td>SharePoint Online</td>
					<td>CVE-2026-70332 is a Server-Side Request Forgery (SSRF) vulnerability in Microsoft SharePoint Online. An unauthenticated attacker can exploit this flaw to perform spoofing over a network, potentially leading to unauthorized information disclosure, interaction with internal services, or further lateral movement within the cloud environment.</td>
			</tr>
			<tr>
					<td>CVE-2026-49163</td>
					<td>0.0</td>
					<td>Application Insights Profiler</td>
					<td>Application Insights Profiler is vulnerable to a path traversal flaw (CWE-22) that allows an authorized attacker to elevate their privileges over a network. This vulnerability indicates improper limitation of a pathname to a restricted directory.</td>
			</tr>
			<tr>
					<td>CVE-2026-62836</td>
					<td>0.0</td>
					<td>Azure SQL Managed Instance</td>
					<td>CVE-2026-62836 identifies a vulnerability in Azure SQL Managed Instance due to improper restriction of communication channels to intended endpoints. This flaw allows an unauthenticated, remote attacker to escalate privileges over a network connection by exploiting the misconfigured communication path.</td>
			</tr>
			<tr>
					<td>CVE-2026-62918</td>
					<td>0.0</td>
					<td>Microsoft Teams</td>
					<td>CVE-2026-62918 is a vulnerability in Microsoft Teams involving improper verification of cryptographic signatures. This flaw allows an unauthorized remote attacker to perform spoofing attacks over a network, potentially leading to unauthorized data manipulation or masquerading within the platform.</td>
			</tr>
	</tbody>
</table>
<h2 id="cve-2026-50481">CVE-2026-50481</h2>
<p>CVE-2026-50481 is a critical vulnerability in Microsoft Azure Active Directory involving the modification of assumed-immutable data (MAID). An authorized attacker can exploit this flaw to escalate privileges within the environment over a network, potentially leading to unauthorized administrative access.</p>
<p>Affected products:</p>
<ul>
<li>Azure Active Directory</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50481">https://nvd.nist.gov/vuln/detail/CVE-2026-50481</a></p>
<h2 id="cve-2026-50515">CVE-2026-50515</h2>
<p>CVE-2026-50515 is a critical deserialization of untrusted data vulnerability in Azure Service Bus that permits an authenticated attacker with low privileges to achieve remote code execution. Detection efforts should focus on monitoring anomalous serialized data payloads sent to service bus endpoints and unexpected process execution spawned by the Azure Service Bus service account.</p>
<p>Affected products:</p>
<ul>
<li>Azure Service Bus</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-50515">https://nvd.nist.gov/vuln/detail/CVE-2026-50515</a></p>
<h2 id="cve-2026-56161">CVE-2026-56161</h2>
<p>CVE-2026-56161 describes an improper access control vulnerability in Microsoft Azure Logic Apps. An authenticated attacker can exploit this vulnerability to disclose sensitive information over a network. The vulnerability carries a CVSS 3.1 base score of 9.6, indicating a critical risk.</p>
<p>Affected products:</p>
<ul>
<li>Azure Logic Apps</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-56161">https://nvd.nist.gov/vuln/detail/CVE-2026-56161</a></p>
<h2 id="cve-2026-59115">CVE-2026-59115</h2>
<p>CVE-2026-59115 is a critical path traversal vulnerability in the Microsoft Entra Provisioning Service (SyncFabric). An authorized attacker can leverage this vulnerability by using a specific input string ('.../...//') to elevate their privileges over a network. The vulnerability has a CVSS base score of 9.9, indicating a significant risk to the integrity, confidentiality, and availability of the affected cloud service.</p>
<p>Affected products:</p>
<ul>
<li>Microsoft Entra Provisioning Service</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-59115">https://nvd.nist.gov/vuln/detail/CVE-2026-59115</a></p>
<h2 id="cve-2026-59118">CVE-2026-59118</h2>
<p>CVE-2026-59118 is an improper authorization vulnerability in Microsoft Power Apps that allows an unauthorized attacker to perform a privilege escalation over a network. The vulnerability carries a CVSS 3.1 base score of 9.3, indicating a critical severity impact on confidentiality and integrity, necessitating restricted access controls within the affected cloud service.</p>
<p>Affected products:</p>
<ul>
<li>Power Apps</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-59118">https://nvd.nist.gov/vuln/detail/CVE-2026-59118</a></p>
<h2 id="cve-2026-62830">CVE-2026-62830</h2>
<p>A vulnerability in the Azure SRE Agent stemming from missing authorization (CWE-862) allows an already authorized network attacker to perform privilege escalation. The vulnerability is rated critical with a CVSS 3.1 score of 9.9, as it enables full scope impact across confidentiality, integrity, and availability within the cloud environment.</p>
<p>Affected products:</p>
<ul>
<li>Azure SRE Agent</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62830">https://nvd.nist.gov/vuln/detail/CVE-2026-62830</a></p>
<h2 id="cve-2026-62873">CVE-2026-62873</h2>
<p>The Microsoft 365 Admin Center is vulnerable to an improper verification of cryptographic signature vulnerability (CWE-347). This flaw allows a remote, unauthorized attacker to elevate their privileges over a network, potentially leading to full compromise of confidentiality, integrity, and availability.</p>
<p>Affected products:</p>
<ul>
<li>Microsoft 365 Admin Center</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62873">https://nvd.nist.gov/vuln/detail/CVE-2026-62873</a></p>
<h2 id="cve-2026-62896">CVE-2026-62896</h2>
<p>Microsoft Teams contains an improper authentication vulnerability that allows an authenticated attacker to perform privilege escalation over a network. This flaw represents a critical security risk due to the potential for unauthorized access elevation within the application environment.</p>
<p>Affected products:</p>
<ul>
<li>Microsoft Teams</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62896">https://nvd.nist.gov/vuln/detail/CVE-2026-62896</a></p>
<h2 id="cve-2026-63508">CVE-2026-63508</h2>
<p>Microsoft Planetary Computer Pro (GeoCatalog) contains a vulnerability due to missing authentication for a critical function. This allows an unauthorized attacker to perform privilege escalation over a network. The vulnerability is classified as critical and has a CVSS base score of 10.0.</p>
<p>Affected products:</p>
<ul>
<li>Microsoft Planetary Computer Pro (GeoCatalog)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-63508">https://nvd.nist.gov/vuln/detail/CVE-2026-63508</a></p>
<h2 id="cve-2026-65667">CVE-2026-65667</h2>
<p>CVE-2026-65667 is a critical security vulnerability in Microsoft Teams involving missing authorization (CWE-862). This flaw allows a remote, unauthenticated attacker to elevate privileges over a network, potentially leading to unauthorized access to sensitive information and system integrity compromises.</p>
<p>Affected products:</p>
<ul>
<li>Microsoft Teams</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-65667">https://nvd.nist.gov/vuln/detail/CVE-2026-65667</a></p>
<h2 id="cve-2026-68823">CVE-2026-68823</h2>
<p>CVE-2026-68823 involves an exposed dangerous method or function in the Azure Confidential Ledger service, which allows an authorized attacker to achieve remote code execution over a network. The vulnerability is classified as CWE-749 and carries a critical CVSS base score of 9.1.</p>
<p>Affected products:</p>
<ul>
<li>Azure Confidential Ledger</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-68823">https://nvd.nist.gov/vuln/detail/CVE-2026-68823</a></p>
<h2 id="cve-2026-70332">CVE-2026-70332</h2>
<p>CVE-2026-70332 is a Server-Side Request Forgery (SSRF) vulnerability in Microsoft SharePoint Online. An unauthenticated attacker can exploit this flaw to perform spoofing over a network, potentially leading to unauthorized information disclosure, interaction with internal services, or further lateral movement within the cloud environment.</p>
<p>Affected products:</p>
<ul>
<li>SharePoint Online</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-70332">https://nvd.nist.gov/vuln/detail/CVE-2026-70332</a></p>
<h2 id="cve-2026-49163">CVE-2026-49163</h2>
<p>Application Insights Profiler is vulnerable to a path traversal flaw (CWE-22) that allows an authorized attacker to elevate their privileges over a network. This vulnerability indicates improper limitation of a pathname to a restricted directory.</p>
<p>Affected products:</p>
<ul>
<li>Application Insights Profiler</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-49163">https://nvd.nist.gov/vuln/detail/CVE-2026-49163</a></p>
<h2 id="cve-2026-62836">CVE-2026-62836</h2>
<p>CVE-2026-62836 identifies a vulnerability in Azure SQL Managed Instance due to improper restriction of communication channels to intended endpoints. This flaw allows an unauthenticated, remote attacker to escalate privileges over a network connection by exploiting the misconfigured communication path.</p>
<p>Affected products:</p>
<ul>
<li>Azure SQL Managed Instance</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62836">https://nvd.nist.gov/vuln/detail/CVE-2026-62836</a></p>
<h2 id="cve-2026-62918">CVE-2026-62918</h2>
<p>CVE-2026-62918 is a vulnerability in Microsoft Teams involving improper verification of cryptographic signatures. This flaw allows an unauthorized remote attacker to perform spoofing attacks over a network, potentially leading to unauthorized data manipulation or masquerading within the platform.</p>
<p>Affected products:</p>
<ul>
<li>Microsoft Teams</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-62918">https://nvd.nist.gov/vuln/detail/CVE-2026-62918</a></p>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>roundup</category></item></channel></rss>