
Two critical CVEs landed against managed AI agent services on 6 August 2026. There was nothing to patch. CVE-2026-62830, Azure SRE Agent: missing authorisation, CVSS 9.9, scope changed. CVE-2026-59118, Copilot Cowork: improper authorisation, 9.3. Both records state the vulnerability has already been fully mitigated by Microsoft and there is no action for users of the service to take. Neither was recorded as publicly disclosed or exploited at release. That is reassuring on likelihood. It is not an assurance that nothing happened in any given tenant, and the disclosure is not designed to answer that. Why it breaks the process: vulnerability management assumes a finding maps to an action. Give it a finding with no action and it either closes the record as not applicable, burying the only signal, or leaves it open forever and corrupts the ageing metric a board reads. The fix is a third disposition: recorded, no customer action available, routed to vendor assurance. Read as a series per provider, these disclosures are the closest thing to direct evidence of how a provider builds, tests and fixes. For an APRA-regulated entity, CPS 234 already covers it. Paragraph 16: assess the third party's information security capability. Paragraph 22: evaluate the design of its controls. Paragraph 28: where relying on its testing, assess whether it is commensurate with the standard's testing requirements. Then the part within reach. Microsoft's own documentation states that Conditional Access policies targeting all users do not include agents' user accounts, that a policy targeting agent identities does not apply to the agent's user account, and that an agent using an API key bypasses token issuance, so the policies do not apply. The vendor owns the code. The customer owns the blast radius.
Post summary
The text announces two critical CVEs affecting managed AI agent services, providing detailed technical information but noting that both have been fully mitigated by the vendor with no action required for users, and confirming no active exploitation or public PoC exists.





