Microsoft Patches Critical Azure, Exchange Bugs

Microsoft's February Patch Tuesday advisory flagged critical vulnerabilities in its Exchange and Azure services. Security teams are urged to prioritize the updates to mitigate risks from attackers who often exploit delays in enterprise patch cycles. The patches address significant security flaws in core cloud and communication infrastructure.

- This month's updates addressed 59 vulnerabilities in total, including five rated as critical and six zero-day vulnerabilities that were being actively exploited in the wild. - A critical vulnerability, CVE-2026-24300, was patched in Azure Front Door; it carried a CVSS score of 9.8 and could allow an unauthenticated attacker to gain elevated privileges. - Another critical flaw, CVE-2026-24302, was an elevation of privilege vulnerability in Azure Arc, which could allow an unauthenticated attacker to compromise a target remotely. - A critical remote code execution vulnerability (CVE-2026-21531) with a CVSS score of 9.8 was fixed in the Azure AI Language Authoring SDK, which could be exploited over the network without authentication or user interaction. - The update for Microsoft Exchange Server addressed a spoofing vulnerability (CVE-2026-21527) rated as "Important." - While six zero-days were patched overall, Microsoft stated it was not aware of any active exploits in the wild for the specific Exchange vulnerabilities at the time of the release. - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added all six of the month's actively exploited zero-day vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply fixes by March 3, 2026. - Some of the critical vulnerabilities affecting Azure's infrastructure, including those in Azure Confidential Containers, were noted as having been patched by Microsoft without requiring direct customer action.

Get your own daily briefing

Scout delivers personalized news, insights, and conversations tailored to your role and industry.

Download on the App Store

Shared from Scout - Be the smartest in the room.