Microsoft and Apple both released urgent security updates on August 7, patching a combined total of vulnerabilities across cloud services, productivity tools, and operating systems.
Microsoft led the disclosures with fixes for more than a dozen vulnerabilities spanning Active Directory, Azure, Entra ID, SharePoint, Teams, and other products. Three flaws received the maximum CVSS severity score of 10 out of 10: CVE-2026-63508, a missing authentication issue in Planetary Computer Pro; CVE-2026-56162, an improper authentication bug in Azure SQL Database; and CVE-2026-65667, a missing authorization flaw in Microsoft Teams. All three could lead to elevation of privilege over the network.
Four additional vulnerabilities scored 9.9 out of 10: CVE-2026-50515 (remote code execution in Azure Service Bus), CVE-2026-62830 (elevation of privilege in Azure SRE Agent), CVE-2026-59115 (elevation of privilege in Entra Provisioning Service), and CVE-2026-50481 (elevation of privilege in Active Directory). All are remotely exploitable without user interaction.
Other critical and high-severity issues patched by Microsoft could lead to information disclosure, remote code execution, elevation of privilege, and spoofing across its product portfolio. The release comes one week after Microsoft addressed over two dozen additional fixes in Office, 365 Apps for Enterprise, Edge, and Azure Cosmos DB.
Apple released a single patch on Thursday for CVE-2026-65400, a vulnerability with a CVSS score of 7.5 that could allow remote attackers to bypass Screen Sharing authentication. An attacker on the same network could authenticate to Screen Sharing on a Mac without valid credentials. Patches were included in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9.
The Apple fix follows the company’s August release that patched dozens of vulnerabilities across iOS 26.6 and macOS Tahoe 26.6. The pace of security updates from both vendors reflects the escalating threat landscape as adversaries target cloud infrastructure and authentication mechanisms with increasing sophistication.
Security researchers emphasized that organizations should prioritize patching the three maximum-severity Microsoft flaws immediately, as they affect widely deployed cloud and identity services. The Azure and Entra ID vulnerabilities in particular could provide attackers with high-impact footholds in enterprise environments.
discussion