Microsoft and Apple Rush Out Security Updates Amid Multiple Vulnerability Risks
Microsoft and Apple have released security updates to address multiple vulnerabilities across their products. The charge was led by Microsoft, which patched over a dozen vulnerabilities across Active Directory, Azure, Entra, SharePoint, Teams, and other products.
Three of the issues, CVE-2026-63508, CVE-2026-56162, and CVE-2026-65667, have a maximum severity rating of 10/10. These flaws could lead to elevation of privilege (EoP) and can be exploited over the network.
Four other flaws, CVE-2026-50515 (RCE in Azure Service Bus), CVE-2026-62830 (EoP in Azure SRE Agent), CVE-2026-59115 (EoP in Entra Provisioning Service), and CVE-2026-50481 (EoP in Active Directory), have a CVSS score of 9.9/10. All four are remotely exploitable.
Apple squashed a single bug on Thursday, tracked as CVE-2026-65400 (CVSS score of 7.5). This vulnerability could allow remote attackers to bypass Screen Sharing authentication. Patches for the security defect were included in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9.