Microsoft and Apple Fix Critical Flaws in Cloud Services, Directories, and Screen Sharing
Microsoft and Apple release critical patches for Azure, Active Directory, and Screen Sharing vulnerabilities, addressing high-severity flaws.
Illustrative image generated with AI
Microsoft Addresses Azure Services and Enterprise Environments
On August 6, Microsoft released security updates for more than a dozen vulnerabilities affecting Active Directory, Azure, Entra, SharePoint, Teams, and other products.
Three flaws received the maximum CVSS score of 10.0 and are remotely exploitable:
- CVE-2026-63508: missing authentication in Planetary Computer Pro, potentially allowing privilege escalation.
- CVE-2026-56162: improper authentication in Azure SQL Database, which could also be exploited to gain elevated privileges.
- CVE-2026-65667: missing authorization in Teams, potentially resulting in privilege escalation.
Microsoft also fixed four vulnerabilities rated CVSS 9.9/10, all remotely exploitable:
- CVE-2026-50515, remote code execution in Azure Service Bus;
- CVE-2026-62830, privilege escalation in Azure SRE Agent;
- CVE-2026-59115, privilege escalation in Entra Provisioning Service;
- CVE-2026-50481, privilege escalation in Active Directory.
The other resolved flaws could lead to information disclosure, remote code execution, privilege escalation, or spoofing attacks. Microsoft has not disclosed the exact affected product versions.
Apple Flaw Allows Screen Sharing Controls to Be Bypassed
Apple fixed CVE-2026-65400, a vulnerability in Screen Sharing with a CVSS score of 7.5/10.
An attacker on the same network could authenticate without valid credentials, bypass access controls, and establish a remote session. The issue is therefore particularly relevant to systems where screen sharing is enabled or accessible over the network.
The fix is included in:
- macOS Tahoe 26.6.1;
- macOS Sequoia 15.7.9;
- macOS Sonoma 14.8.9.
Apple released the update on Thursday, approximately one week after the fixes included in iOS 26.6 and macOS Tahoe 26.6.
Which Environments Are Most Exposed
The Microsoft vulnerabilities affect cloud infrastructure, enterprise directories, collaboration tools, and services responsible for authentication, authorization, and administrative privileges.
A successful attack could allow an attacker to execute code, access confidential information, or obtain elevated permissions in Azure, Entra, Active Directory, and Teams environments. Network accessibility increases the priority of addressing systems exposed to the Internet or to untrusted networks.
For Apple, the risk involves unauthorized remote access to Screen Sharing sessions by an attacker already present on the network.
Updates and Checks to Perform
Administrators should:
- apply the available Microsoft updates to all affected products;
- update Macs to macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, or macOS Sonoma 14.8.9;
- prioritize Azure, Entra, Active Directory, and Teams services exposed to the network;
- review logs for unusual access to Screen Sharing, Azure, Entra, Active Directory, and Teams;
- pay particular attention to unusual authentication events, privilege changes, and unexpected remote connections.
The exact vulnerable Microsoft product versions are unknown. Accordingly, updates should be deployed through the standard official patch-management channels.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2026-63508Critical10.0Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-56162Critical10.0Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-65667Critical10.0Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.
- CVE-2026-50515Critical9.9Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.
- CVE-2026-62830Critical9.9Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.
- CVE-2026-59115Critical9.9'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
- CVE-2026-50481Critical9.9Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
- CVE-2026-65400Critical9.8An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.
