Three CVSS 10.0 vulnerabilities in Planetary Computer Pro, Azure SQL Database, and Teams got quietly patched on August 6 — completely outside Microsoft's scheduled August 11 Patch Tuesday.
Microsoft's scheduled Patch Tuesday for August isn't until August 11. That didn't stop the company from shipping fixes on August 6 for three vulnerabilities that scored a perfect 10.0 out of 10.0 on the CVSS scale — the maximum severity rating that exists — plus four more scoring 9.9. Apple followed the next day with its own fix for a bug that lets an attacker on the same network log into Screen Sharing without a valid password at all.
The three perfect scores
A CVSS score of 10.0 means every dimension the scoring system measures is maxed out: no privileges required, no user interaction needed, total compromise of confidentiality, integrity, and availability. It's the score reserved for 'anyone on the internet can just walk in.' Microsoft handed out three of them in one advisory.
The August 6 CVSS 10.0 and 9.9 bugs
CVE-2026-63508
CVE
Planetary Computer Pro
Product
10.0
CVSS
Missing authentication — full unauthenticated access
Notice what these have in common: every one lives in Microsoft's cloud stack — Azure, Entra, Teams — not a legacy on-prem Windows component, and the pattern isn't unique to Microsoft this month. Cisco's own trio of 9.9-CVSS bugs in Catalyst SD-WAN and IOS XE landed a few weeks earlier, and Veeam ONE's perfect-10 RCE before that — the products managing everything else are becoming August 2026's highest-value single targets.
The Apple fix nobody's talking about
Apple's patch is a single bug, and on paper a 7.5 CVSS score looks almost boring next to Microsoft's 10.0s. It shouldn't. CVE-2026-65400 is an authentication bypass in macOS's Screen Sharing — Apple's built-in remote desktop feature — that lets an attacker already on the same network as the target Mac authenticate without a valid password. Apple's fix note says it was addressed 'with improved state management,' which is vague in the way Apple advisories usually are, but the practical read is simple: on unpatched Macs with Screen Sharing enabled, network proximity was doing the job a password should have been doing.
CVE-2026-65400 let a network-adjacent attacker skip the Screen Sharing login entirely on unpatched Macs. · Unsplash
What this means for the actual Patch Tuesday, five days out
This out-of-band batch doesn't replace August's regular Patch Tuesday, due August 11 — it's in addition to it. Help Net Security's own forecast for that release flags a second SharePoint vulnerability, held back from disclosure in July as part of an embargoed two-bug remote code execution chain, as the headline item still coming. If your org runs SharePoint Server on-prem or hybrid, that's the one to actually block time for next week, not this week's cloud-service fixes. SecurityWeek's report has the full advisory breakdown for both companies.
Severity at a glance
Planetary Computer Pro10.0
Azure SQL Database10.0
Microsoft Teams10.0
Azure Service Bus9.9
Entra Provisioning9.9
Active Directory9.9
macOS Screen Sharing7.5
Verdict
What to patch first
If you administer Azure/Entra/Teams tenants, treat this as a today-not-this-week update — the three 10.0s require zero privileges and zero user interaction, which is exactly the combination that turns into automated mass-scanning within days. Mac fleets with Screen Sharing enabled should update to 26.6.1 / 15.7.9 / 14.8.9 on the same timeline. Then block calendar time for August 11 separately — this batch doesn't cover it.
Best for: IT admins managing Microsoft cloud tenants or Mac fleets
Were any of these vulnerabilities exploited before the patch shipped?
No confirmed active exploitation or zero-day status has been reported for any of the eight CVEs in this batch, based on Microsoft's and Apple's own advisories as of publication.
Is this part of the regular August Patch Tuesday?
No — Microsoft's scheduled Patch Tuesday for August 2026 is August 11. This was a separate, out-of-band release on August 6 covering Azure, Entra, and Teams specifically.
Do I need to do anything if I don't use Azure or Entra directly?
If your organization uses Microsoft 365, Teams, or any Azure-hosted service through a vendor, you're likely covered automatically once Microsoft patches the cloud service itself — these aren't client-side updates you need to push in most cases, unlike a typical Windows patch.
What should I check for the Apple fix?
Confirm your Mac fleet is on macOS Tahoe 26.6.1, Sequoia 15.7.9, or Sonoma 14.8.9 or later. If Screen Sharing isn't in active use, disabling it removes the exposure entirely regardless of patch status.
Three perfect-10 bugs in one advisory is rare enough that it's worth asking why now, even without a confirmed exploitation event driving it. My guess, and it's a guess: whatever internal or external report flagged Planetary Computer Pro, Azure SQL Database, and Teams together suggested enough of a realistic attack path that Microsoft didn't want to sit on it for five more days. Patch the cloud-tenant bugs today, update Mac fleets on the same pass, and treat August 11 as its own separate event — the still-unpatched half of the SharePoint RCE chain, and whatever else lands alongside it, is shaping up to be the bigger story of the two. If you're also running Linux fleets, don't forget the XFS root privilege escalation bug patched this week — patch season apparently isn't just a Microsoft thing in August 2026.