Microsoft publishes seven critical cloud-service CVEs already fixed on its side: Partner Center (CVSS 10.0), Bookings (9.9), Dataverse and Azure App Service (9.8), Azure SRE Agent (9.6), API Center and Event Grid; no customer action needed
Microsoft's Security Update Guide added seven cloud-service CVEs on 8 October 2026 (US time), all rated Critical by Microsoft and all marked as already fully mitigated by Microsoft with no action for customers; they are published for transparency under its cloud-service CVE policy. They are CVE-2026-96207, improper certificate validation in Microsoft Partner Center allowing privilege escalation by an unauthenticated attacker (CVSS 10.0); CVE-2026-94510, an authorisation bypass through a user-controlled key in Microsoft Bookings (9.9); CVE-2026-88131, deserialisation of untrusted data allowing unauthenticated code execution in Microsoft Dataverse (9.8); CVE-2026-77900, missing authentication allowing unauthenticated code execution in Azure App Service (9.8); CVE-2026-69435, missing authorisation in Azure SRE Agent allowing an authenticated attacker to escalate privileges (9.6); CVE-2026-83943, information disclosure in Azure API Center (8.7); and CVE-2026-83947, spoofing in Azure Event Grid (7.7). Microsoft says none were publicly disclosed or exploited. Primary: Microsoft Security Response Center.
- Product
- Microsoft cloud services — Partner Center, Bookings, Dataverse, Azure App Service, Azure SRE Agent, Azure API Center, Azure Event Grid
- Versions
- n/a — Microsoft-hosted services, fixed by Microsoft
- CVSS
- (CVE-2026-96207); 9.9 (CVE-2026-94510); 9.8 (CVE-2026-88131, CVE-2026-77900); 9.6 (CVE-2026-69435); 8.7 (CVE-2026-83943); 7.7 (CVE-2026-83947)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N - Exploited in Australia?
- unknown
- Patch to
- No customer action required; Microsoft has fixed all seven. Partners and tenants may still want to review Partner Center, Bookings and App Service audit logs for unusual activity from before the fix dates.
Primary: Microsoft Security Response Center — CVE-2026-96207, Microsoft Partner Center elevation of privilege (8 Oct 2026) · Vendor: Microsoft Security Response Center — CVE-2026-77900, Azure App Service remote code execution (8 Oct 2026) · CVE: CVE-2026-96207, CVE-2026-94510, CVE-2026-88131, CVE-2026-77900, CVE-2026-69435, CVE-2026-83943, CVE-2026-83947 · Microsoft Security Response Center — CVE-2026-94510, Microsoft Bookings elevation of privilege (8 Oct 2026)
