Microsoft's September Patch Tuesday fixes three max-severity Azure identity flaws

The three maximum-severity flaws strike at the core of Azure's identity infrastructure — Azure AD B2C, Entra ID, and Azure AI Language — the systems that gate access across Microsoft's cloud. Two carry a perfect CVSS 10.0 score. Microsoft says all were remediated server-side, meaning customers did not need to take action, but the concentration of critical identity bugs in a single cycle is what alarmed security teams. The 964 total CVEs set a record for volume.
Identity is the highest-value target in cloud security: a flaw in Entra ID or B2C can translate to broad unauthorized access across tenants, and the inclusion of Azure AI Language signals that AI services are now part of the critical attack surface. Server-side fixes limit exposure, but the pattern raises questions about whether the rapid expansion of Azure AI offerings is outpacing security hardening.
The disclosure that Azure topped $100 billion in annual revenue underscores the stakes — Azure is now core infrastructure for a huge swath of enterprise AI, making its identity layer a systemic risk. Security researchers framed it as 'the pillar cracks three ways,' noting that concentrated identity vulnerabilities in the same patch cycle are rare and consequential. Enterprises will scrutinize whether these were independently discovered or related, and whether Microsoft's server-side remediation was complete before disclosure. Watch for follow-on advisories and any evidence of exploitation in the wild.