Microsoft’s Two-Track Patch Tuesday: Cloud Identity Flaws Fixed Before Disclosure, Windows Still Catching Up

The September 2026 security cycle has unveiled a distinct bifurcation in Microsoft’s approach to vulnerability management, particularly in the realm of identity services. This dual strategy is evident as security professionals navigate a landscape where cloud-side identity services benefit from silent, server-side mitigations, while on-premises Windows infrastructure adheres to the traditional Patch Tuesday schedule.

Recent Vulnerabilities and Mitigations

On September 3, Microsoft proactively addressed nine vulnerabilities, all of which were cloud-side and required no action from customers. Among these, two vulnerabilities stood out with a CVSS score of 10.0. The first, CVE-2026-83711, involved an Azure AD B2C elevation of privilege flaw that allowed unauthorized attackers to bypass authorization through user-controlled keys. The second, CVE-2026-70352, was found in Azure AI Language Authoring, exposing a critical function due to missing authentication. Additionally, CVE-2026-83941, an Entra ID elevation of privilege vulnerability rated at 9.9, and CVE-2026-80098, a flaw in Copilot Studio related to improper cryptographic signature verification, further underscored the identity layer’s vulnerability to exploitation.

Five days later, the September 8 Patch Tuesday update presented a more conventional profile, addressing 70 CVEs, including 13 classified as critical and 57 as important. This release focused primarily on the on-premises stack, featuring CVE-2026-83939, which rectified an elevation of privilege issue in the Windows Secure Kernel Mode. It also included fixes for CVE-2026-83498 and CVE-2026-83501, both concerning vulnerabilities within Windows VBS Enclave. This stark contrast between the rapid, invisible patching of cloud services and the manual deployment required for local kernel-level components highlights the challenges faced by identity architects in maintaining security across diverse environments.

Adding complexity to the timeline was the out-of-band handling of CVE-2026-69414, known as ShieldBreak. This elevation of privilege vulnerability within the Defender Malware Protection Engine, which grants SYSTEM privileges, was patched out-of-band on September 3. However, it had been publicly exposed for approximately three weeks, with a proof-of-concept available since August 11. This delay exemplifies the operational risks associated with relying on engine-level updates for critical security components, revealing a significant exposure window that conventional Patch Tuesday cycles fail to address.

Addressing the Authentication Gap

These developments are part of a broader narrative surrounding the ongoing authentication gap, a systemic issue where identity verification is often treated as optional across both open-source AI middleware and enterprise infrastructure. Recent analyses have highlighted how missing authentication in critical cloud functions, coupled with a reliance on legacy authentication methods, indicates that the industry has yet to fully embrace identity as a foundational security requirement. This trend is evident in incidents such as PaperCut’s two-minute RCE chain and N-able’s third attack wave within six weeks.

In light of these vulnerabilities, Microsoft has begun to shift its Self-Service Password Reset (SSPR) enforcement as of September 7. Passkeys will now serve as the default, with a planned phase-out of SMS and voice-based authentication by February 2027. This policy change aims to transition away from phishable, legacy credentials towards more secure, hardware-backed identity solutions.

While cloud-side mitigations effectively safeguard the provider’s infrastructure, they also place the onus of visibility on practitioners, who must now manage silent fixes alongside traditional patch management. As the authentication gap continues to manifest in both cloud and on-premises environments, the emphasis must shift from reactive patching to proactive identity hardening. Practitioners are encouraged to prioritize the transition to passkeys and to audit their reliance on legacy authentication protocols ahead of the 2027 deadline.

Winsage
Microsoft’s Two-Track Patch Tuesday: Cloud Identity Flaws Fixed Before Disclosure, Windows Still Catching Up