Daily briefing · August 20, 2026

Microsoft Azure and Entra Hit with Multiple CVSS 10.0 Flaws; One Already Flagged by VulnCheck Before CISA

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention1 seen before CISA

August 20, 2026 demands attention from every organization running Microsoft cloud infrastructure. Ten critical vulnerabilities were disclosed today across Azure and Microsoft services, five of them scoring the maximum CVSS 10.0, with CVE-2026-69836 in Microsoft Entra already flagged by VulnCheck as under active exploitation before any official CISA confirmation — a strong early warning signal that attackers are moving faster than the official disclosure cycle.

Today’s brief
  • CVE-2026-69836 (Microsoft Entra, CVSS 10.0) is already being exploited in the wild per VulnCheck, ahead of CISA acknowledgment — patch immediately.
  • Five vulnerabilities scored CVSS 10.0 today, all in Microsoft cloud services: Entra, Azure Arc, Azure Web Apps, Azure Managed Instance for Apache Cassandra, and Exchange Online.
  • Brazilian targets are under sustained ransomware pressure, with government and technology sectors hit by groups including emperor, dragonforce, and thegentlemen.
  • IBM AIX and PowerVM VIOS (CVSS 9.9) round out the day's critical list, adding enterprise on-premises infrastructure to the risk surface.
78
critical
1
Actively exploited
1
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-69836◆ VulnCheckCVSS 10affects Microsoft Entra
Deserialization of untrusted data in Microsoft Entra ID enables unauthenticated remote code execution (CVSS 10.0), and VulnCheck has already observed exploitation in the wild before CISA issued any formal alert — this is the highest-urgency item of the day and should be treated as a zero-day in practice.
2
CVE-2026-69555CVSS 10affects Azure ARC
An incorrect authorization flaw in Azure Arc allows any unauthorized network attacker to escalate privileges to a critical level (CVSS 10.0); organizations relying on Arc for hybrid and multi-cloud management face immediate risk of full environment compromise.
3
CVE-2026-65816CVSS 10affects Azure Web Apps
A name/reference resolution flaw in Azure Arc (affecting Azure Web Apps) enables privilege escalation without authentication (CVSS 10.0); combined with CVE-2026-69555, attackers have two distinct vectors into Arc-managed environments.
4
CVE-2026-65770CVSS 10affects Azure Managed Instance for Apache Cassandra
Argument injection in Azure Managed Instance for Apache Cassandra allows unauthenticated remote code execution at CVSS 10.0, putting managed database infrastructure directly at risk of full takeover with no credentials required.
5
CVE-2026-65801CVSS 10affects Microsoft Exchange Online
A server-side request forgery (SSRF) vulnerability in Microsoft Exchange Online enables unauthenticated privilege escalation (CVSS 10.0), potentially allowing attackers to pivot laterally across cloud tenants or access internal services from Exchange's trusted network position.
6
CVE-2026-18835CVSS 9.9affects AIX
IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 contain an OS command injection flaw (CVSS 9.9) exploitable by remote authenticated attackers; enterprises running AIX-based workloads or VIOS hypervisors should treat this as an insider-threat-amplifier risk.
7
CVE-2026-68782CVSS 9.9affects Azure SQL Database
SQL injection in Azure SQL Database allows an authenticated attacker to escalate privileges (CVSS 9.9); while a credential is required, compromised accounts or insider threats could leverage this to move laterally within database environments.
8
CVE-2026-63509CVSS 9.9affects Microsoft Fabric
A relative path traversal in Microsoft Fabric allows an authenticated attacker to elevate privileges (CVSS 9.9), threatening the integrity of analytics workloads and data assets hosted within Microsoft's unified data platform.
9
CVE-2026-69851CVSS 9.9affects Microsoft Entra
SSRF in Azure Active Directory (Microsoft Entra) enables authenticated privilege escalation (CVSS 9.9); paired with CVE-2026-69836, the Entra attack surface today is exceptionally broad and deserves urgent review.
10
CVE-2026-68789CVSS 9.9affects Azure SQL Database
A second SQL injection vulnerability in Azure SQL Database (CVSS 9.9) allows authenticated attackers to elevate privileges, reinforcing the need for least-privilege database access controls and immediate patching across Azure SQL environments.
Ransomware today

Recently, the grupo emperador claimed the Prefeitura Municipal de Arcos, a Brazilian government entity, while dragonforce listed Vermont XCenter as a victim — both signals that ransomware operators continue to prioritize Brazilian targets across public and private sectors. Looking at the past 30 days, Section9 leads activity with 6 known victims (all in Brazil), followed by thegentlemen (5 in Brazil) and Global Secret Group (4 in Brazil), painting a consistent picture of Brazil-focused ransomware campaigns.

Prefeitura Municipal de Arcos BRemperador · Government & Defense
Vermont XCenter BRdragonforce
Section9 6thegentlemen 5Global Secret Group 4L Group 2direwolf 2emperador 1
Active groups & APTs

Several threat actor handles — including kazu, kelvinsecurity, krybit, lamashtu, linkc, and Iran-linked blackshadow — have been updated or flagged as active in tracking systems, though no confirmed victims have been attributed to them yet. The presence of blackshadow, associated with Iranian state-nexus operations, warrants monitoring particularly for organizations in critical infrastructure and government sectors, as this group has historically pivoted quickly from reconnaissance to destructive action.

Brazil focus

Brazil is experiencing sustained and multi-sector threat actor pressure: in recent weeks, confirmed ransomware victims include TOTVS (technology, hit by direwolf), VR Advogados (professional services, Barracuda), Vector Two Technology and Megalaser Industria Metalurgica (both hit by thegentlemen), Chat Jurídico (direwolf), and tecnoabi.com (m3rx), alongside the latest government hit in Arcos. The breadth of targeted sectors — government, manufacturing, legal, and technology — underscores that no vertical in Brazil can consider itself a low-priority target.

Prefeitura Municipal de Arcosemperador · Government & Defense
Vermont XCenterdragonforce
TOTVSdirewolf · Technology
VR AdvogadosBarracuda · Professional Services
tecnoabi.comm3rx · Technology
Vector Two Technologythegentlemen · Technology
Megalaser Industria Metalurgica LTDAthegentlemen · Manufacturing
Chat Jurídicodirewolf · Professional Services
Today’s recommendation: Organizations using any Microsoft Azure or Entra service should prioritize patching CVE-2026-69836 immediately given confirmed pre-CISA exploitation, then work through the remaining CVSS 10.0 flaws in Azure Arc, Exchange Online, and Cassandra Managed Instance as an urgent batch — waiting for a scheduled maintenance window is not advisable given the active threat signal.
With five CVSS 10.0 vulnerabilities and confirmed early exploitation in your cloud identity and infrastructure layer, now is the moment to validate whether your own exposure to these services has already been assessed and whether compensating controls are actually in place.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share