The Fault Line Spreads: Azure’s September CVE Cluster Now Covers PostgreSQL and Billing

Two newly identified Critical CVEs have expanded the scope of Microsoft’s September identity infrastructure vulnerabilities, bringing the total to over ten verified weaknesses across more than ten distinct services. This escalation signifies a shift from the identity control plane into both the data tier and the financial layer of Azure.

Azure Vulnerability Cluster Expands to Data and Financial Tiers

The Azure Database for PostgreSQL has been found to be vulnerable to CVE-2026-85878, an Improper Authorization flaw (CWE-285) that carries a CVSS score of 9.9. Concurrently, Azure Billing is impacted by CVE-2026-62874, which presents an Insufficient Data Authenticity Verification issue (CWE-345) with a maximum CVSS score of 10.0. Both vulnerabilities were disclosed on September 18 and have been validated by Tenable and MITRE. These findings confirm that the current Azure vulnerability cluster has progressed beyond the initial identity control plane to encompass the data and financial layers of the cloud environment.

CVE-2026-85878 allows an authorized attacker to elevate privileges over the network with minimal complexity and no user interaction (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). The scope-changed metric indicates that the exploit crosses security boundaries. In contrast, CVE-2026-62874 is more critical, requiring no authentication whatsoever (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L). An unauthenticated attacker on the network can elevate privileges and potentially jeopardize the financial integrity of enterprise tenants. As of the last check, Microsoft had not yet released an MSRC advisory for CVE-2026-62874, although records from Tenable and MITRE were available.

Timeline of the Cluster

The vulnerability cluster first emerged during the Patch Tuesday cycles on September 3 and September 8. Initial reports highlighted critical flaws in core services, including CVE-2026-83711 (Azure AD B2C, CVSS 10.0), CVE-2026-70352 (Azure AI Language, CVSS 10.0), and CVE-2026-83941 (Entra ID, CVSS 9.9). Additionally, CVE-2026-62916 in Entra ID (CVSS 9.1) was noted for pre-patch exploitation reports. Other September disclosures included CVE-2026-69857 (Azure Cosmos DB, CVSS 8.5) and CVE-2026-69854 (Spring Cloud Azure, CVSS 9.0).

Activity heightened between September 17 and 18, with the introduction of CVE-2026-77903 (Microsoft Dataverse, CVSS 9.0) and CVE-2026-69843 (Microsoft Fabric, CVSS 10.0) arriving in close succession. Notably, the billing vulnerability was initially deemed unrelated to the Fabric disclosure but has since been confirmed as a standalone critical issue. Furthermore, CVE-2026-85889 (Azure AI Foundry, CVSS 10.0) remains unverified pending confirmation from MSRC and GitHub.

Widening Attack Surface

The initial wave of vulnerabilities targeted the identity control plane, specifically Azure AD B2C and Entra ID. The subsequent wave extended into AI services, including AI Language and AI Foundry. The third wave impacted the data and analytics tier, affecting services such as Dataverse, Fabric, PostgreSQL, and Cosmos DB. Now, with Azure Billing marking a fourth category, the attack surface has broadened from authentication concerns to encompass trust in AI endpoints, data storage locations, and billing verification processes.

Across these ten or more verified CVEs, a common structural pattern emerges: failures in authentication or authorization logic that permit attackers to bypass trust boundaries without requiring credentials. Notably, seven out of the ten vulnerabilities are unauthenticated. All issues were addressed through server-side fixes by Microsoft, necessitating no action from customers. The extensive range of affected services—spanning ten distinct Azure offerings—suggests that these vulnerabilities are not isolated implementation errors but rather indicative of a shared architectural dependency on authentication logic that has not evolved in tandem with service expansion.

What to Watch

  • MSRC for CVE-2026-62874 and CVE-2026-85889: The billing service currently lacks a published MSRC advisory. AI Foundry remains unconfirmed by primary sources, both requiring resolution.
  • Exploitation telemetry: CVE-2026-62916 (Entra ID) has reported instances of pre-patch exploitation. It will be important to monitor whether the newly disclosed data-tier and billing CVEs attract similar activity.
  • Cross-service chaining: Microsoft Fabric integrates data engineering, science, and warehousing under a unified platform. An unauthenticated bypass in Fabric, combined with a billing-layer bypass, could expose both data and cost controls.
  • Next Patch Tuesday cycle: The September cluster spans two Patch Tuesday cycles along with multiple out-of-band disclosures. Observing whether the October cycle continues this trend or stabilizes will be crucial in determining if this represents an acceleration or a peak in vulnerabilities.
Tech Optimizer
The Fault Line Spreads: Azure’s September CVE Cluster Now Covers PostgreSQL and Billing