Dataverse

Tech Optimizer
September 28, 2026
Two newly identified Critical CVEs have expanded Microsoft's September identity infrastructure vulnerabilities to over ten verified weaknesses across more than ten distinct services. The Azure Database for PostgreSQL is vulnerable to CVE-2026-85878, an Improper Authorization flaw (CWE-285) with a CVSS score of 9.9. Azure Billing is impacted by CVE-2026-62874, which presents an Insufficient Data Authenticity Verification issue (CWE-345) with a CVSS score of 10.0. Both vulnerabilities were disclosed on September 18 and validated by Tenable and MITRE. CVE-2026-85878 allows an authorized attacker to elevate privileges over the network with minimal complexity, while CVE-2026-62874 requires no authentication, enabling unauthenticated attackers to jeopardize financial integrity. The vulnerability cluster first emerged during the Patch Tuesday cycles on September 3 and September 8, with initial reports highlighting critical flaws in core services. Other September disclosures include CVE-2026-83711 (Azure AD B2C, CVSS 10.0), CVE-2026-70352 (Azure AI Language, CVSS 10.0), CVE-2026-83941 (Entra ID, CVSS 9.9), CVE-2026-62916 (Entra ID, CVSS 9.1), CVE-2026-69857 (Azure Cosmos DB, CVSS 8.5), and CVE-2026-69854 (Spring Cloud Azure, CVSS 9.0). Activity heightened between September 17 and 18 with the introduction of CVE-2026-77903 (Microsoft Dataverse, CVSS 9.0) and CVE-2026-69843 (Microsoft Fabric, CVSS 10.0). The attack surface has broadened from authentication concerns to encompass trust in AI endpoints, data storage locations, and billing verification processes. Seven out of the ten vulnerabilities are unauthenticated, and all issues were addressed through server-side fixes by Microsoft. The extensive range of affected services suggests these vulnerabilities indicate a shared architectural dependency on authentication logic.
Winsage
May 21, 2025
Microsoft Dataverse is a secure and scalable platform that integrates enterprise data with agent functionalities, serving as the backbone for organizations to manage business and operational data. It powers Microsoft Copilot Studio, enabling developers to create agents that execute adaptive tasks while ensuring human oversight. Key features include AI-powered search, prompt columns for embedding generative AI, and the Dataverse Model Context Protocol (MCP) server, which transforms structured data into interactive knowledge for agents. The MCP server offers capabilities such as querying data, engaging with knowledge sources, creating/updating records, and executing custom prompts. Dataverse knowledge is integrated into Copilot Studio, connecting structured and unstructured data from various sources to create a unified knowledge network. Data in Dataverse is pre-indexed for near-real-time analytics, and integration with Microsoft Fabric allows for easy exploration of this data. Dynamics 365 data is now accessible within Microsoft 365 Copilot, streamlining workflows. New knowledge sources and connectors have been introduced, including Snowflake, SAP, and Confluence, enhancing agent capabilities. The Power Platform connector SDK simplifies the integration of external structured data into Power Apps and Dataverse. A centralized Tools hub in Copilot Studio allows for the management of reusable functionalities across agents. Additionally, three new managed agents are available in preview, designed to automate document workflows, generate executive briefs, and process inbound leads, facilitating quick implementation and scalability for organizations.
Search