
Azure Entra ID bug CVE-2025-59218 (CVSS 9.6) enables unauthenticated privilege escalation, alongside new SSRF and infinite loop issues in API services. Apply vendor fixes. #Vulnerability https://threatcluster.io/cluster/multiple-high-severity-vulnerabilities-discovered-in-api-and-67eae827
Post summary
Azure Entra ID has a high‑severity CVE‑2025‑59218 causing unauthenticated privilege escalation, SSRF, and API infinite loops; Microsoft has released patches that should be applied immediately.
