The bigger issue is not one broken product. It is a cluster of remotely reachable authentication and authorization failures across Microsoft’s cloud and identity stack, which can let a network attacker jump into higher privilege without first stealing a password. That puts the management plane, not just a single server, in scope for unauthorized access and privilege escalation.
Microsoft patched three 10 flaws in Planetary Computer Pro, Azure SQL Database, and Teams, plus four 9.9 bugs in Azure Service Bus, Azure SRE Agent, Entra Provisioning Service, and Active Directory. All are remotely exploitable, and Microsoft also fixed other critical and high-severity issues across Azure, Entra, SharePoint, and related services. Apple separately patched CVE-2026-65400, where a network attacker could bypass Screen Sharing authentication on macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9.