Microsoft, Apple rush patches for critical enterprise flaws

Microsoft patched more than a dozen vulnerabilities across Active Directory, Azure, Entra, SharePoint and Teams, including three rated 10.0; Apple fixed a macOS Screen Sharing bypass.

Microsoft on Thursday released security updates that address more than a dozen vulnerabilities across Active Directory, Azure, Entra, SharePoint, Teams and other products. The fixes cover a mix of on-premises and cloud services used in enterprise environments.

Three vulnerabilities carry the maximum CVSS score of 10.0. They are CVE-2026-63508, a missing authentication issue in Planetary Computer Pro; CVE-2026-56162, an improper authentication flaw in Azure SQL Database; and CVE-2026-65667, a missing authorization bug in Microsoft Teams. Microsoft’s advisory notes these defects can be exploited over a network and may lead to elevation of privilege.

Four additional flaws scored 9.9: CVE-2026-50515 (remote code execution in Azure Service Bus), CVE-2026-62830 (elevation of privilege in the Azure SRE Agent), CVE-2026-59115 (elevation of privilege in the Entra Provisioning Service) and CVE-2026-50481 (elevation of privilege in Active Directory). All four are listed as remotely exploitable.

The updates released Thursday include other critical- and high-severity fixes that address remote code execution, information disclosure, privilege escalation and spoofing. The release follows a round of Microsoft patches issued about a week earlier that targeted Office, 365 Apps for Enterprise, Edge and Azure Cosmos DB.

Apple issued a separate update that fixes a Screen Sharing authentication bypass tracked as CVE-2026-65400 with a CVSS score of 7.5. The correction is included in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9 and macOS Sonoma 14.8.9. Apple’s advisory states, “An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.”

CVSS scores range from 0 to 10 and are calculated from factors such as exploitability and impact. Remote code execution (RCE) means an attacker could run code on a vulnerable system, while elevation of privilege (EoP) means a user or process could gain higher-level access than intended.

Both Microsoft and Apple published technical details and CVE identifiers in their advisories. Administrators and users are advised to apply the available updates and review vendor guidance for specific mitigation steps and deployment priorities.

The disclosures list product-specific patches and technical descriptions for each flaw so IT teams can identify affected systems and schedule updates accordingly.

Articles by this author