# Microsoft Patch Tuesday: Critical Azure and Entra ID Flaws

> Microsoft rolls out 22 new security patches addressing critical elevation of privilege and remote code execution vulnerabilities across Azure and Entra ID.

- Published: 2026-08-21T08:31:20.000Z
- Severity: low
- Category: Vulnerabilities
- Tags: Microsoft Azure, Entra ID, Exchange, Zero-Day, Elevation of Privilege
- CVEs: CVE-2026-69502 (CVSS 10), CVE-2026-69555 (CVSS 10), CVE-2026-65816 (CVSS 10), CVE-2026-65801 (CVSS 10), CVE-2026-65770 (CVSS 10), CVE-2026-69836 (CVSS 10), CVE-2026-68782 (CVSS 9.8), CVE-2026-63509 (CVSS 9.8), CVE-2026-69851 (CVSS 9.8), CVE-2026-68789 (CVSS 9.8), CVE-2026-69400 (CVSS 9.8), CVE-2026-62834 (CVSS 9.8), CVE-2026-66309 (CVSS 9.8), CVE-2026-24301 (CVSS 7.8), CVE-2026-69414 (CVSS 7.8)
- Author: Runtime Rebel Intel
- Primary source: https://www.securityweek.com/microsoft-rolls-out-22-fresh-security-patches/
- Canonical: https://runtimerebel.com/blog/microsoft-patch-tuesday-critical-azure-and-entra-id-flaws

## Key points

- Immediate impact: Microsoft has released 22 security updates addressing severe flaws across Azure, Entra ID, Exchange, and other cloud products.
- Affected systems: Specific cloud components including Azure SQL Database, Azure Arc, Exchange Online, Entra ID, and Microsoft Fabric.
- Remediation: Review Microsoft advisory guidance and verify server-side mitigations where applicable, though most cloud fixes require no direct customer action.

## Overview of Microsoft Security Updates

According to [SecurityWeek](https://www.securityweek.com/microsoft-rolls-out-22-fresh-security-patches/), Microsoft has announced a fresh batch of 22 security updates targeting severe vulnerabilities across a wide array of enterprise products. The majority of these patches resolve critical and high-severity flaws impacting core cloud services, including Microsoft Azure, Entra ID, Exchange, Microsoft Fabric, and Partner Center products.

While many vulnerabilities carry maximum severity ratings, Microsoft has noted that no active customer action is required for a large portion of these defects because the company has deployed the necessary mitigations directly on the server side.

## Technical Details and Analysis

The newly disclosed batch includes several maximum-severity flaws carrying a [CVSS](/glossary#cvss) score of 10 out of 10. Among these are elevation of privilege (EoP) bugs affecting [CVE-2026-69502](https://nvd.nist.gov/vuln/detail/CVE-2026-69502) in Azure SQL Database, [CVE-2026-69555](https://nvd.nist.gov/vuln/detail/CVE-2026-69555) and [CVE-2026-65816](https://nvd.nist.gov/vuln/detail/CVE-2026-65816) in Azure Arc, and [CVE-2026-65801](https://nvd.nist.gov/vuln/detail/CVE-2026-65801) in Exchange Online.

Additional maximum-severity issues involve remote code execution ([RCE](/glossary#rce)) flaws. These include [CVE-2026-65770](https://nvd.nist.gov/vuln/detail/CVE-2026-65770) affecting Azure Managed Instance for Apache Cassandra and [CVE-2026-69836](https://nvd.nist.gov/vuln/detail/CVE-2026-69836) in Entra ID.

### Additional Critical and High-Severity Flaws

Beyond the primary RCE and EoP entries, Microsoft resolved seven other critical elevation of privilege vulnerabilities across cloud platforms:

* [CVE-2026-68782](https://nvd.nist.gov/vuln/detail/CVE-2026-68782) and [CVE-2026-68789](https://nvd.nist.gov/vuln/detail/CVE-2026-68789) in Azure SQL Database
* [CVE-2026-63509](https://nvd.nist.gov/vuln/detail/CVE-2026-63509) in Microsoft Fabric
* [CVE-2026-69851](https://nvd.nist.gov/vuln/detail/CVE-2026-69851) in Entra ID
* [CVE-2026-69400](https://nvd.nist.gov/vuln/detail/CVE-2026-69400) in Azure Logic Apps
* [CVE-2026-62834](https://nvd.nist.gov/vuln/detail/CVE-2026-62834) in Azure Data Factory
* [CVE-2026-66309](https://nvd.nist.gov/vuln/detail/CVE-2026-66309) in Azure SQL Database

Furthermore, high-severity vulnerabilities were addressed in Azure Virtual Machines, Microsoft Partner Center, Azure Stack HCI, Azure Data Manager for Energy, Copilot in Azure, and Windows Remote Help Defense. Earlier in the week, Microsoft also patched a high-severity [command injection](/glossary#command-injection) bug in Copilot tracked as [CVE-2026-24301](https://nvd.nist.gov/vuln/detail/CVE-2026-24301), which could permit remote information disclosure.

### The 'ShieldBreak' [Zero-Day](/glossary#zero-day)

Microsoft is actively working on updates for a public zero-day Defender [exploit](/glossary#exploit) known as 'ShieldBreak', discovered by security researcher Nightmare Eclipse (Chaotic Eclipse). Tracked as [CVE-2026-69414](https://nvd.nist.gov/vuln/detail/CVE-2026-69414), this high-severity elevation of privilege [vulnerability](/glossary#vulnerability) affects the Microsoft [Malware](/glossary#malware) Protection Engine.

## Actionable Recommendations

Security teams should review the latest Microsoft security advisories to confirm which cloud assets require manual intervention versus those managed automatically via server-side updates.

* **Audit Cloud Deployments:** Verify administrative configurations across Azure tenants, Entra ID environments, and Azure Arc connected machines to ensure security baselines are maintained.
* **Monitor [Endpoint](/glossary#endpoint) Protections:** Track updates to the Microsoft Malware Protection Engine to ensure systems are protected against the ShieldBreak vulnerability once patches are generally available.
* **Review Copilot Security:** Ensure environments utilizing Copilot in Azure are evaluated for exposure relating to command injection vulnerabilities.

**Related:** [Zero-Day Acquisition Firm Raises Red Flags: Trust and Supply Chain Risks](/blog/zero-day-acquisition-firm-raises-red-flags-trust-and-supply-chain-risks), [Confused Deputy Flaws in Google Cloud & Azure: Admin Bypass](/blog/confused-deputy-flaws-in-google-cloud-azure-admin-bypass)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/microsoft-patch-tuesday-critical-azure-and-entra-id-flaws
