
⚠️ MICROSOFT DISCLOSES 5 CRITICAL CLOUD-SERVICE FLAWS — PARTNER CENTER RATED CVSS 10.0 Microsoft published five critical CVEs on Oct 8 affecting hosted Microsoft services: • CVE-2026-96207 (CVSS 10.0) Partner Center: improper certificate validation, unauthenticated network privilege escalation • CVE-2026-94510 (CVSS 9.9) Bookings: authorization bypass via user-controlled key • CVE-2026-77900 (CVSS 9.8) Azure App Service for Linux: missing authentication, code execution • CVE-2026-88131 (CVSS 9.8) Dataverse: deserialization of untrusted data, RCE • CVE-2026-69435 (CVSS 9.6) Azure SRE Agent: missing authorization, privilege escalation by an authenticated attacker Fixes are deployed on Microsoft's side; no public exploit or in-the-wild exploitation reported so far. Admins should review MSRC entries for any tenant-side guidance. Primary: msrc[.]microsoft[.]com/update-guide/vulnerability/CVE-2026-96207 #DDW #DarkWeb #Microsoft #Azure #CVE #CloudSecurity #CyberSecurity


