A CVSS 9.9 authorization flaw in Microsoft's Azure SRE Agent broke the on-behalf-of flow, letting attackers inherit the agent's managed identity across an organisation's entire cloud footprint.
A CVSS 9.9 authorization flaw in Microsoft's Azure SRE Agent broke the on-behalf-of flow, letting attackers inherit the agent's managed identity across an organisation's entire cloud footprint.
Beyond the record 570-CVE headline, Microsoft's July 2026 Patch Tuesday patched nine vulnerabilities across its AI product suite — including a Critical RCE in Copilot for desktop triggered by visiting a malicious website, and a CVSS 9.9 elevation of privilege in Azure OpenAI.
Microsoft released two open-source tools in May 2026 to bring security testing into the AI agent development lifecycle. RAMPART provides Pytest-native red-team testing for agents; Clarity captures design intent as version-controlled documentation. Both target the gap between building agents and securing them.
Microsoft's July 2026 Patch Tuesday dropped patches for 570+ vulnerabilities, with two actively exploited. The bigger story: AI is making Microsoft's own exploitability ratings meaningless.
Microsoft Incident Response published research showing how attackers can hijack agentic AI workflows by planting hidden instructions in MCP tool description fields — a vector that bypasses most current enterprise controls because each step the agent takes looks routine.
A three-flaw chain in Microsoft AutoGen Studio's MCP WebSocket surface lets a malicious webpage execute arbitrary commands on the host via an AI browsing agent. Microsoft patched in June 2026.
June 2026 Patch Tuesday set an all-time record with 198 CVEs, including three zero-days. FIRST.org now forecasts 66,000 CVEs for the full year. AI vulnerability discovery tools are reshaping what patch management looks like.
Two critical CVEs in Microsoft Semantic Kernel let attackers chain prompt injection into arbitrary file writes and code execution. Patch to .NET SDK 1.71.0 and Python SDK 1.39.4 immediately.
A self-replicating worm compromised 73 Microsoft GitHub repositories on June 5, 2026, via stolen contributor PAT and malicious AI coding tool configs. Contained in 105 seconds.