Microsoft just fixed three perfect-10 bugs in Azure and Teams — five days before Patch Tuesday

Three CVSS 10.0 vulnerabilities in Planetary Computer Pro, Azure SQL Database, and Teams got quietly patched on August 6 — completely outside…

Aliteq
Priya Nair · Software & Systems Editor

What got patched, and when

Microsoft patched three CVSS 10.0 vulnerabilities on August 6, 2026 — five days ahead of its scheduled August 11 Patch Tuesday: CVE-2026-63508 (Planetary Computer Pro, missing authentication),…

What got patched, and when

Four more vulnerabilities scored 9.9: remote code execution in Azure Service Bus (CVE-2026-50515), and elevation-of-privilege bugs in Azure SRE Agent (CVE-2026-62830), Entra Provisioning Service…

What got patched, and when

Apple shipped macOS Tahoe 26.6.1, Sequoia 15.7.9, and Sonoma 14.8.9 on August 7 to fix CVE-2026-65400 (CVSS 7.5), a Screen Sharing bug letting a network attacker authenticate without valid…

What got patched, and when

None of the eight vulnerabilities carries a confirmed active-exploitation or zero-day designation as of publication — this reads as proactive patching, not incident response.

What got patched, and when

Microsoft's actual August Patch Tuesday, due August 11, is separately expected to include a SharePoint remote code execution chain carried over from an embargoed July disclosure.

What to patch first

If you administer Azure/Entra/Teams tenants, treat this as a today-not-this-week update — the three 10.0s require zero privileges and zero user interaction, which is exactly the combination that…

Aliteq

Read the full story

Microsoft just fixed three perfect-10 bugs in Azure and Teams — five days before Patch Tuesday

Read the full story on Aliteq