← All briefings

Microsoft Entra ID / Azure Active Directory B2C · Azure AI Language Authoring · Microsoft Entra ID

Date: 2026-09-04 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership

Executive Summary

New intelligence highlights critical privilege-escalation and authentication-bypass vulnerabilities in Microsoft Entra and Azure services, alongside multiple high-impact flaws in developer tooling. Cisco Nexus 9000 exposure is also significant: a newly reported CVSS 9.8 vulnerability reportedly enables unauthenticated remote code execution as root on affected Silicon One-based switches. Organizations should prioritize internet-facing identity, network infrastructure, CI/CD and developer platforms, while continuing emergency remediation of previously reported KEV and actively exploited vulnerabilities.

Critical Vulnerabilities

CVE-2026-83711 — Microsoft Entra ID / Azure Active Directory B2C

  • Severity: CVSS 10.0
  • EPSS: 0 — no exploitation probability currently reported by EUVD
  • Technical detail: An authorization-bypass vulnerability involving a user-controlled key allows an unauthorized attacker to elevate privileges over a network. The available description does not specify the required tenant configuration or affected identity flows; treat externally reachable B2C deployments as priority exposure points.
  • Exploitation status: No exploitation reported in the supplied intelligence.
  • Remediation: Apply Microsoft’s security update or service-side fix when available. Review Entra B2C administrative activity, anomalous role assignments, changes to application registrations and unusual authentication events. Validate that Microsoft’s mitigation has propagated across affected tenants.

CVE-2026-70352 — Azure AI Language Authoring

  • Severity: CVSS 10.0
  • EPSS: 0 — no exploitation probability currently reported by EUVD
  • Technical detail: Missing authentication for a critical function permits an unauthorized network attacker to elevate privileges. Risk is greatest where Azure AI Language Authoring resources, management endpoints or associated service principals are broadly accessible or insufficiently restricted.
  • Exploitation status: No exploitation reported in the supplied intelligence.
  • Remediation: Apply Microsoft’s fix and verify the status of affected Azure resources. Audit service-principal permissions, authoring operations, token issuance and configuration changes. Restrict administrative access through least privilege, conditional access and network controls.

CVE-2026-62916 — Microsoft Entra ID

  • Severity: CVSS 9.1
  • EPSS: 0 — no exploitation probability currently reported by EUVD
  • Technical detail: An authentication bypass using an alternate path or channel may allow an unauthorized attacker to elevate privileges over a network. The supplied record does not identify the affected protocol or path; identity-provider telemetry should therefore be reviewed broadly for unexpected privilege changes.
  • Exploitation status: No exploitation reported in the supplied intelligence.
  • Remediation: Apply Microsoft’s remediation and confirm tenant protection. Investigate privileged-role assignments, authentication-policy changes, newly registered credentials and suspicious sign-ins. Revoke anomalous sessions and rotate credentials if unauthorized access is suspected.

CVE-2026-20212 — Cisco Nexus 9000 Switches

  • Severity: CVSS 9.8
  • EPSS: Not available
  • Technical detail: Reporting indicates a critical vulnerability affecting 10 Silicon One-based Nexus 9000 switches that can permit an unauthenticated remote attacker to execute code as root. The supplied data does not include the precise vulnerable release range or attack prerequisites; network exposure and device model should be confirmed against Cisco’s advisory.
  • Exploitation status: Cisco has released patches; exploitation was not confirmed in the supplied intelligence.
  • Remediation: Apply Cisco’s fixed release urgently. Restrict management and control-plane access, validate device integrity and review administrator logins, configuration changes, unexpected processes and outbound connections. Treat affected switches as potentially compromised if anomalous activity is identified.

CVE-2026-62681 / CVE-2026-62682 / CVE-2026-72717 — Orval OpenAPI Code Generator

  • Severity: CVSS 9.3 for each listed vulnerability
  • EPSS: 0.52, 0.50 and 0.55 respectively — high exploitation probability
  • Technical detail: Malicious OpenAPI specifications can trigger remote code execution through unescaped request-URL template literals or schema defaults during code generation or import. The flaws affect Orval versions below 8.21.0 and are especially relevant to CI/CD runners, build agents and developer workstations that process third-party specifications.
  • Exploitation status: No confirmed exploitation reported in the supplied intelligence; EPSS is elevated.
  • Remediation: Upgrade Orval to 8.21.0 or later. Treat external OpenAPI files as untrusted, isolate generation jobs, restrict CI runner privileges and review recent build scripts, generated code and outbound connections from developer tooling.

ONGOING

  • CVE-2026-63520 (Microsoft SharePoint): Active exploitation and public PoC remain reported; patch and inspect for web shells.
  • CVE-2026-8452 (Citrix NetScaler ADC/Gateway): Actively exploited; verify patching and management-interface restrictions.
  • CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF): Chained exploitation remains reported; patch before the 2026-09-14 KEV deadline.
  • CVE-2026-60004 (Gitea): KEV remediation deadline passed; patch and inspect Git hook directories.
  • CVE-2026-49869 (Kestra), CVE-2026-82329 (JFrog Artifactory) and CVE-2026-9586 (Sangoma Switchvox): KEV remediation deadline is 2026-09-05; patch or isolate immediately.
  • CVE-2026-83548 / CVE-2026-83549 (SonicWall SMA1000): Actively exploited chain to unauthenticated RCE; patch and assess for compromise.
  • CVE-2026-0768 (Langflow): Active exploitation reported; upgrade and rotate exposed cloud/API credentials.
  • CVE-2023-49105 (ownCloud), CVE-2026-19478 (GitLab), CVE-2019-1068 (Microsoft SQL Server) and CVE-2026-53362 (Linux Kernel): Active or KEV-listed remediation remains required.

European Advisories

  • WID-SEC-2026-3164 (Langflow): New BSI advisory reports that a remote, unauthenticated attacker can execute arbitrary code with administrator privileges. Covered by the ongoing Langflow entry above; prioritize internet-exposed instances and credential rotation.
  • WID-SEC-2026-3172 (IBM i): New high-severity advisory covering multiple flaws with potential denial of service, security-control bypass and database or memory manipulation. Review IBM i inventories and apply vendor updates.
  • WID-SEC-2026-3170 (BigBlueButton): New advisory covering authenticated vulnerabilities involving XSS, security-control bypass and information disclosure. Patch conferencing platforms and restrict administrative access.
  • WID-SEC-2026-3169 (VMware Fusion and Workstation): Local vulnerabilities may allow code execution. Update managed developer and administrator endpoints.
  • WID-SEC-2026-3168 (Drupal extensions): Multiple flaws may enable access-control bypass, sensitive-data disclosure, account takeover and unauthorized content or payment changes. Inventory extensions and update or remove unsupported components.
  • WID-SEC-2026-3166 (Jenkins): Multiple vulnerabilities affect Jenkins and plugins, including code execution, data manipulation, XSS and session takeover. Prioritize internet-facing controllers and review plugin inventories.
  • WID-SEC-2026-3165 (n8n): Authenticated flaws may permit security-control bypass, code execution or denial of service. Restrict workflow administration and update deployments.
  • WID-SEC-2026-3158 / WID-SEC-2026-3157 (F5 BIG-IP / Cisco Nexus): New advisories cover administrator privilege escalation and code execution; Cisco Nexus is detailed in Critical Vulnerabilities.
  • WID-SEC-2026-3159 / WID-SEC-2026-3153 (RPM / zlib): Both remain unpatched according to BSI; apply vendor fixes when released and assess exposure in Linux fleets.
  • WID-SEC-2026-1686 (Samba), WID-SEC-2026-1190 (GNU libc) and WID-SEC-2026-1312 (GnuTLS): Updated advisories; reassess against current Linux and Unix maintenance plans.

Active Threats and Campaigns

  • RMM phishing campaign — NEW CONTEXT: A campaign using remote-management lures has been linked to 601 cases across 46 countries. Enforce phishing-resistant MFA, block unauthorized RMM installation and hunt for unexpected remote-support services and sessions.
  • Node.js malware delivery — NEW: Attackers are abusing the trusted node.exe runtime to deploy payloads against government, technology and hospitality organizations. Monitor unusual Node.js child processes, script execution, persistence and outbound connections.
  • Developer supply-chain compromise — NEW: Coder registry infrastructure was reportedly compromised to deliver malicious Terraform modules containing credential-stealing code. Validate module sources and hashes, restrict CI/CD egress and rotate credentials used by affected pipelines.
  • Langflow exploitation — ONGOING: Attackers continue targeting CVE-2026-0768 to steal OpenAI and AWS credentials; revoke exposed keys and review flow-execution logs.
  • Virtualizor malicious update campaign — ONGOING: Validate packages against trusted hashes and investigate VPS management hosts.

Security News and Context

  1. Patch or mitigate Microsoft Entra and Azure AI Language exposures; review privileged identity changes.
  2. Patch affected Cisco Nexus 9000 switches and inspect management-plane activity.
  3. Upgrade Orval to 8.21.0+; isolate OpenAPI processing and audit CI runners.
  4. Patch Langflow, Kestra, Artifactory and Switchvox before the 2026-09-05 deadlines.
  5. Hunt for unauthorized Node.js execution, RMM installations and Terraform module changes.
  6. Rotate cloud, CI/CD and developer credentials exposed through compromised tools or infostealers.
  7. Continue remediation of previously reported items: CVE-2026-63520, CVE-2026-8452, PaperCut, Gitea, ownCloud, GitLab, SQL Server and Linux Kernel vulnerabilities.