Daily briefing · August 20, 2026
Microsoft Azure and Entra Hit with Multiple CVSS 10.0 Flaws; One Already Flagged by VulnCheck Before CISA
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention1 seen before CISA
August 20, 2026 demands attention from every organization running Microsoft cloud infrastructure. Ten critical vulnerabilities were disclosed today across Azure and Microsoft services, five of them scoring the maximum CVSS 10.0, with CVE-2026-69836 in Microsoft Entra already flagged by VulnCheck as under active exploitation before any official CISA confirmation — a strong early warning signal that attackers are moving faster than the official disclosure cycle.
Today’s brief
- CVE-2026-69836 (Microsoft Entra, CVSS 10.0) is already being exploited in the wild per VulnCheck, ahead of CISA acknowledgment — patch immediately.
- Five vulnerabilities scored CVSS 10.0 today, all in Microsoft cloud services: Entra, Azure Arc, Azure Web Apps, Azure Managed Instance for Apache Cassandra, and Exchange Online.
- Brazilian targets are under sustained ransomware pressure, with government and technology sectors hit by groups including emperor, dragonforce, and thegentlemen.
- IBM AIX and PowerVM VIOS (CVSS 9.9) round out the day's critical list, adding enterprise on-premises infrastructure to the risk surface.
Critical highlights
1
Deserialization of untrusted data in Microsoft Entra ID enables unauthenticated remote code execution (CVSS 10.0), and VulnCheck has already observed exploitation in the wild before CISA issued any formal alert — this is the highest-urgency item of the day and should be treated as a zero-day in practice.
2
An incorrect authorization flaw in Azure Arc allows any unauthorized network attacker to escalate privileges to a critical level (CVSS 10.0); organizations relying on Arc for hybrid and multi-cloud management face immediate risk of full environment compromise.
3
A name/reference resolution flaw in Azure Arc (affecting Azure Web Apps) enables privilege escalation without authentication (CVSS 10.0); combined with CVE-2026-69555, attackers have two distinct vectors into Arc-managed environments.
4
CVE-2026-65770CVSS 10affects Azure Managed Instance for Apache Cassandra Argument injection in Azure Managed Instance for Apache Cassandra allows unauthenticated remote code execution at CVSS 10.0, putting managed database infrastructure directly at risk of full takeover with no credentials required.
5
A server-side request forgery (SSRF) vulnerability in Microsoft Exchange Online enables unauthenticated privilege escalation (CVSS 10.0), potentially allowing attackers to pivot laterally across cloud tenants or access internal services from Exchange's trusted network position.
6
IBM AIX 7.2, 7.3 and PowerVM VIOS 4.1 contain an OS command injection flaw (CVSS 9.9) exploitable by remote authenticated attackers; enterprises running AIX-based workloads or VIOS hypervisors should treat this as an insider-threat-amplifier risk.
7
SQL injection in Azure SQL Database allows an authenticated attacker to escalate privileges (CVSS 9.9); while a credential is required, compromised accounts or insider threats could leverage this to move laterally within database environments.
8
A relative path traversal in Microsoft Fabric allows an authenticated attacker to elevate privileges (CVSS 9.9), threatening the integrity of analytics workloads and data assets hosted within Microsoft's unified data platform.
9
SSRF in Azure Active Directory (Microsoft Entra) enables authenticated privilege escalation (CVSS 9.9); paired with CVE-2026-69836, the Entra attack surface today is exceptionally broad and deserves urgent review.
10
A second SQL injection vulnerability in Azure SQL Database (CVSS 9.9) allows authenticated attackers to elevate privileges, reinforcing the need for least-privilege database access controls and immediate patching across Azure SQL environments.
Ransomware today
Recently, the grupo emperador claimed the Prefeitura Municipal de Arcos, a Brazilian government entity, while dragonforce listed Vermont XCenter as a victim — both signals that ransomware operators continue to prioritize Brazilian targets across public and private sectors. Looking at the past 30 days, Section9 leads activity with 6 known victims (all in Brazil), followed by thegentlemen (5 in Brazil) and Global Secret Group (4 in Brazil), painting a consistent picture of Brazil-focused ransomware campaigns.
Prefeitura Municipal de Arcos BRemperador · Government & Defense
Vermont XCenter BRdragonforce
Section9 6thegentlemen 5Global Secret Group 4L Group 2direwolf 2emperador 1
Active groups & APTs
Several threat actor handles — including kazu, kelvinsecurity, krybit, lamashtu, linkc, and Iran-linked blackshadow — have been updated or flagged as active in tracking systems, though no confirmed victims have been attributed to them yet. The presence of blackshadow, associated with Iranian state-nexus operations, warrants monitoring particularly for organizations in critical infrastructure and government sectors, as this group has historically pivoted quickly from reconnaissance to destructive action.
Brazil focus
Brazil is experiencing sustained and multi-sector threat actor pressure: in recent weeks, confirmed ransomware victims include TOTVS (technology, hit by direwolf), VR Advogados (professional services, Barracuda), Vector Two Technology and Megalaser Industria Metalurgica (both hit by thegentlemen), Chat Jurídico (direwolf), and tecnoabi.com (m3rx), alongside the latest government hit in Arcos. The breadth of targeted sectors — government, manufacturing, legal, and technology — underscores that no vertical in Brazil can consider itself a low-priority target.
Prefeitura Municipal de Arcosemperador · Government & Defense
Vermont XCenterdragonforce
TOTVSdirewolf · Technology
VR AdvogadosBarracuda · Professional Services
tecnoabi.comm3rx · Technology
Vector Two Technologythegentlemen · Technology
Megalaser Industria Metalurgica LTDAthegentlemen · Manufacturing
Chat Jurídicodirewolf · Professional Services
Today’s recommendation: Organizations using any Microsoft Azure or Entra service should prioritize patching CVE-2026-69836 immediately given confirmed pre-CISA exploitation, then work through the remaining CVSS 10.0 flaws in Azure Arc, Exchange Online, and Cassandra Managed Instance as an urgent batch — waiting for a scheduled maintenance window is not advisable given the active threat signal.
With five CVSS 10.0 vulnerabilities and confirmed early exploitation in your cloud identity and infrastructure layer, now is the moment to validate whether your own exposure to these services has already been assessed and whether compensating controls are actually in place.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →