ELEVATED 8 min read 7 Aug 2026

CVE-2026-68823 Azure Confidential Ledger Remote Code Execution Vulnerability Leads Today's Security Review

Threat Level: Elevated Tags: cve-2026-68823, cwe-749, cve-2026-50515, cwe-502, cve-2026-62896, cve-2026-62918, cve-2026-65667, cwe-287, cve-2026-50481, cwe-471

Key findings
01
CVE-2026-68823 Azure Confidential Ledger Remote Code Execution Vulnerability
CRITICAL
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The assigned identifier is CVE-2026-68823.
02
CVE-2026-50515 Azure Service Bus Remote Code Execution Vulnerability
CRITICAL
Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. CVE coverage: CVE-2026-50515.
03
Multiple vulnerabilities in Microsoft Teams
CRITICAL
CVE coverage: CVE-2026-62896, CVE-2026-62918, CVE-2026-65667. The cited advisories disclose: Elevation of Privilege Vulnerability; Spoofing Vulnerability; Elevation of Privilege Vulnerability.
04
CVE-2026-50481 Azure Active Directory Elevation of Privilege Vulnerability
CRITICAL
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. CVE coverage: CVE-2026-50481.
05
CVE-2026-70332 Microsoft Office SharePoint Spoofing Vulnerability
CRITICAL
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. CVE coverage: CVE-2026-70332.
06
CVE-2026-62830 Azure SRE Agent Elevation of Privilege Vulnerability
CRITICAL
Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. CVE coverage: CVE-2026-62830.
07
CVE-2026-56162 Azure SQL Database Elevation of Privilege Vulnerability
CRITICAL
Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. CVE coverage: CVE-2026-56162.
08
CVE-2026-62873 Microsoft 365 Admin Center Elevation of Privilege Vulnerability
CRITICAL
Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. CVE coverage: CVE-2026-62873.
09
CVE-2026-56161 Azure Logic Apps Information Disclosure Vulnerability
CRITICAL
Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. CVE coverage: CVE-2026-56161.
10
CVE-2026-63508 Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability
CRITICAL
Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. CVE coverage: CVE-2026-63508.
11
CVE-2026-59118 Microsoft Power Apps Elevation of Privilege Vulnerability
CRITICAL
Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network. CVE coverage: CVE-2026-59118.
12
CVE-2026-59115 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
CRITICAL
'.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. CVE coverage: CVE-2026-59115.
13
Still active: New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
CRITICAL
First reported 2026-08-06; ongoing coverage. cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity.
14
CVE-2026-62836 Azure SQL Managed Instance Elevation of Privilege Vulnerability
HIGH
Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network. CVE coverage: CVE-2026-62836.
15
CVE-2026-65668 Microsoft Purview eDiscovery Elevation of Privilege Vulnerability
HIGH
Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. CVE coverage: CVE-2026-65668.

Executive assessment

Today's brief leads with CVE-2026-68823 Azure Confidential Ledger Remote Code Execution Vulnerability. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.

Finding 01 — CVE-2026-68823 Azure Confidential Ledger Remote Code Execution Vulnerability

What changed: This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability.

Technical evidence: CVE-2026-68823; CVSS v3.1 9.1; weakness ['CWE-749']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-68823 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: msrc.microsoft.com](<https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68823>)

Finding 02 — CVE-2026-50515 Azure Service Bus Remote Code Execution Vulnerability

What changed: Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. CVE coverage: CVE-2026-50515.

Technical evidence: CVE-2026-50515; CVSS v3.1 9.9; weakness ['CWE-502']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-50515 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: msrc.microsoft.com](<https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50515>)

Finding 03 — Multiple vulnerabilities in Microsoft Teams

What changed: CVE coverage: CVE-2026-62896, CVE-2026-62918, CVE-2026-65667. The cited advisories disclose: Elevation of Privilege Vulnerability; Spoofing Vulnerability; Elevation of Privilege Vulnerability.

Technical evidence: CVE-2026-62896; CVSS v3.1 9.6; weakness ['CWE-287']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-62896 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: msrc.microsoft.com](<https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62896>)

Finding 04 — CVE-2026-50481 Azure Active Directory Elevation of Privilege Vulnerability

What changed: Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. CVE coverage: CVE-2026-50481.

Technical evidence: CVE-2026-50481; CVSS v3.1 9.9; weakness ['CWE-471']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-50481 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: msrc.microsoft.com](<https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50481>)

Finding 05 — CVE-2026-70332 Microsoft Office SharePoint Spoofing Vulnerability

What changed: Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. CVE coverage: CVE-2026-70332.

Technical evidence: CVE-2026-70332; CVSS v3.1 9.6; weakness ['CWE-918']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-70332 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: msrc.microsoft.com](<https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70332>)

Finding 06 — CVE-2026-62830 Azure SRE Agent Elevation of Privilege Vulnerability

What changed: Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network. CVE coverage: CVE-2026-62830.

Technical evidence: CVE-2026-62830; CVSS v3.1 9.9; weakness ['CWE-862']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-62830 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: msrc.microsoft.com](<https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62830>)

Finding 07 — CVE-2026-56162 Azure SQL Database Elevation of Privilege Vulnerability

What changed: Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. CVE coverage: CVE-2026-56162.

Technical evidence: CVE-2026-56162; CVSS v3.1 10; weakness ['CWE-287']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-56162 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: msrc.microsoft.com](<https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56162>)

Finding 08 — CVE-2026-62873 Microsoft 365 Admin Center Elevation of Privilege Vulnerability

What changed: Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. CVE coverage: CVE-2026-62873.

Technical evidence: CVE-2026-62873; CVSS v3.1 9.8; weakness ['CWE-347']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-62873 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: msrc.microsoft.com](<https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62873>)

Finding 09 — CVE-2026-56161 Azure Logic Apps Information Disclosure Vulnerability

What changed: Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. CVE coverage: CVE-2026-56161.

Technical evidence: CVE-2026-56161; CVSS v3.1 9.6; weakness ['CWE-284']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-56161 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: msrc.microsoft.com](<https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56161>)

Finding 10 — CVE-2026-63508 Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability

What changed: Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. CVE coverage: CVE-2026-63508.

Technical evidence: CVE-2026-63508; CVSS v3.1 10; weakness ['CWE-306']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-63508 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: msrc.microsoft.com](<https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63508>)

Finding 11 — CVE-2026-59118 Microsoft Power Apps Elevation of Privilege Vulnerability

What changed: Improper authorization in Microsoft Power Apps allows an unauthorized attacker to elevate privileges over a network. CVE coverage: CVE-2026-59118.

Technical evidence: CVE-2026-59118; CVSS v3.1 9.3; weakness ['CWE-285']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-59118 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: msrc.microsoft.com](<https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59118>)

Finding 12 — CVE-2026-59115 Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability

What changed: '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. CVE coverage: CVE-2026-59115.

Technical evidence: CVE-2026-59115; CVSS v3.1 9.9; weakness ['CWE-35']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-59115 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: msrc.microsoft.com](<https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59115>)

Finding 13 — Still active: New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

Coverage status: First reported 2026-08-06; ongoing coverage.

What changed: cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries.

Technical evidence: CVE-2026-58048; CVSS v4.0 9.4; weakness ['CWE-89']; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-58048 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: thehackernews.com](<https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html>)

Finding 14 — CVE-2026-62836 Azure SQL Managed Instance Elevation of Privilege Vulnerability

What changed: Improper restriction of communication channel to intended endpoints in Azure SQL Managed Instance allows an unauthorized attacker to elevate privileges over a network. CVE coverage: CVE-2026-62836.

Technical evidence: CVE-2026-62836; CVSS v3.1 8.7; weakness ['CWE-923']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-62836 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

[Evidence source: msrc.microsoft.com](<https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62836>)

Finding 15 — CVE-2026-65668 Microsoft Purview eDiscovery Elevation of Privilege Vulnerability

What changed: Improper access control in Microsoft Purview eDiscovery allows an authorized attacker to elevate privileges over a network. CVE coverage: CVE-2026-65668.

Technical evidence: CVE-2026-65668; CVSS v3.1 8.8; weakness ['CWE-284']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-65668 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: msrc.microsoft.com](<https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65668>)

cve-2026-50481cve-2026-50515cve-2026-56161cve-2026-56162cve-2026-58048cve-2026-59115cve-2026-59118cve-2026-62830cve-2026-62836cve-2026-62873

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.