Microsoft Quietly Patches 8 Critical Cloud Vulnerabilities
Microsoft has recently addressed eight critical vulnerabilities impacting various cloud and Software-as-a-Service (SaaS) offerings, including prominent services like Power Pages, Entra ID, Azure Resource Manager, and several Azure networking components. These security advisories were issued on May 22, 2026, detailing flaws with significant severity.
A notable aspect of these patches is their high-risk classification: five of the identified vulnerabilities were assigned a Common Vulnerability Scoring System (CVSS) rating of 10, the highest possible score, while the remaining three received scores of 9.1 or higher. This indicates that these flaws could potentially allow for severe impacts, such as remote code execution or significant privilege escalation, if exploited.
Specific vulnerabilities include a Power Pages command injection (CVE-2026-23652, CVSS 10), an Azure Orbital Spatio RCE (CVE-2026-40412, CVSS 10), and an Azure Resource Manager privilege escalation (CVE-2026-47280, CVSS 10). Other critical issues involved Entra ID/Azure AD B2C privilege escalation (CVE-2026-33843, CVSS 9.1), Azure Virtual Network Gateway RCE (CVE-2026-40411, CVSS 9.9), and a 365 Copilot for iOS command injection (CVE-2026-41090, CVSS 9.3). An additional Entra ID privilege escalation (CVE-2026-42901, CVSS 10) was also patched.
Unlike the traditional "Patch Tuesday" cycle, which typically involves downloadable updates for Windows and requires administrators to apply them, these advisories pertain to Microsoft-managed cloud services. The remediation process for these SaaS vulnerabilities followed Microsoft's standard server-side patching pattern, meaning the updates were applied directly by Microsoft to their cloud infrastructure. This approach minimizes the operational burden on customers, as they do not need to take direct action to secure their services against these specific flaws.
At the time of reporting, there was no public proof-of-concept code, evidence of active exploitation, or listing on the CISA Known Exploited Vulnerabilities catalog for any of these eight flaws. This suggests that the patches were deployed proactively, addressing the vulnerabilities before they could be widely exploited by malicious actors. The incident underscores the continuous efforts by major cloud providers to maintain the security integrity of their vast and complex cloud environments.
Read original source