Azure Identity Infrastructure Cracked Three Ways in Record-Breaking Patch Tuesday
Azure's identity infrastructure has been hit with three high-severity vulnerabilities in a single Patch Tuesday, all of which were patched server-side without requiring customer action. The issues, rated CVSS 9.9-10.0, affect Azure AD B2C, Entra ID, and Azure AI Language.
The September 2026 Patch Tuesday cycle saw a record-breaking 964 total CVEs, with the three vulnerabilities all resolved through server-side remediation. This approach shifts the burden of discovery and resolution entirely to the service provider.
Microsoft's disclosure of these flaws out-of-band on September 3, 2026, underscores the concentration of risk within core authentication and authorization services. The presence of a 10.0-rated vulnerability in Azure AD B2C, which is in maintenance mode, raises questions about the security posture of legacy identity services approaching end of support.