Microsoft and Apple Fix Critical Flaws in Cloud Services, Directories, and Screen Sharing

Microsoft and Apple release critical patches for Azure, Active Directory, and Screen Sharing vulnerabilities, addressing high-severity flaws.

Microsoft and Apple Fix Critical Flaws in Cloud Services, Directories, and Screen Sharing
Vulnerabilities

Illustrative image generated with AI

Microsoft Addresses Azure Services and Enterprise Environments

On August 6, Microsoft released security updates for more than a dozen vulnerabilities affecting Active Directory, Azure, Entra, SharePoint, Teams, and other products.

Three flaws received the maximum CVSS score of 10.0 and are remotely exploitable:

  • CVE-2026-63508: missing authentication in Planetary Computer Pro, potentially allowing privilege escalation.
  • CVE-2026-56162: improper authentication in Azure SQL Database, which could also be exploited to gain elevated privileges.
  • CVE-2026-65667: missing authorization in Teams, potentially resulting in privilege escalation.

Microsoft also fixed four vulnerabilities rated CVSS 9.9/10, all remotely exploitable:

  • CVE-2026-50515, remote code execution in Azure Service Bus;
  • CVE-2026-62830, privilege escalation in Azure SRE Agent;
  • CVE-2026-59115, privilege escalation in Entra Provisioning Service;
  • CVE-2026-50481, privilege escalation in Active Directory.

The other resolved flaws could lead to information disclosure, remote code execution, privilege escalation, or spoofing attacks. Microsoft has not disclosed the exact affected product versions.

Apple Flaw Allows Screen Sharing Controls to Be Bypassed

Apple fixed CVE-2026-65400, a vulnerability in Screen Sharing with a CVSS score of 7.5/10.

An attacker on the same network could authenticate without valid credentials, bypass access controls, and establish a remote session. The issue is therefore particularly relevant to systems where screen sharing is enabled or accessible over the network.

The fix is included in:

  • macOS Tahoe 26.6.1;
  • macOS Sequoia 15.7.9;
  • macOS Sonoma 14.8.9.

Apple released the update on Thursday, approximately one week after the fixes included in iOS 26.6 and macOS Tahoe 26.6.

Which Environments Are Most Exposed

The Microsoft vulnerabilities affect cloud infrastructure, enterprise directories, collaboration tools, and services responsible for authentication, authorization, and administrative privileges.

A successful attack could allow an attacker to execute code, access confidential information, or obtain elevated permissions in Azure, Entra, Active Directory, and Teams environments. Network accessibility increases the priority of addressing systems exposed to the Internet or to untrusted networks.

For Apple, the risk involves unauthorized remote access to Screen Sharing sessions by an attacker already present on the network.

Updates and Checks to Perform

Administrators should:

  1. apply the available Microsoft updates to all affected products;
  2. update Macs to macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, or macOS Sonoma 14.8.9;
  3. prioritize Azure, Entra, Active Directory, and Teams services exposed to the network;
  4. review logs for unusual access to Screen Sharing, Azure, Entra, Active Directory, and Teams;
  5. pay particular attention to unusual authentication events, privilege changes, and unexpected remote connections.

The exact vulnerable Microsoft product versions are unknown. Accordingly, updates should be deployed through the standard official patch-management channels.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Related topicsMicrosoftApplesecurity flawscloud servicesActive DirectoryAzureScreen Sharingcritical vulnerabilities
Back to home