MICROSOFT has announced 22 new security updates addressing critical vulnerabilities in its products, including Microsoft Azure, Entra ID, and Exchange. The updates resolve serious issues such as elevation of privilege and remote code execution, with several flaws rated 10/10 on the CVSS scale. Key vulnerabilities include CVE-2026-69502 and CVE-2026-69836. Most patches require no customer action as they are deployed server-side.
The company is also working on patches for the 'ShieldBreak' exploit, with a CVSS score of 7.8. Additionally, Microsoft resolved a command injection vulnerability in Copilot.