Microsoft's Cloud Is On Fire: What the Azure CVSS 10.0 Pair Means for UK Small Business
Two vulnerabilities scored CVSS 10.0 in Microsoft’s cloud infrastructure this week. The maximum possible score. Both allow an attacker to escalate privileges without authentication.
Let that settle for a moment before we move on.
What Actually Happened
On 3 September 2026, the National Vulnerability Database published two critical flaws affecting Microsoft’s cloud services.
CVE-2026-70352 affects Azure AI Language. The flaw is described as a missing authentication for a critical function. An unauthenticated attacker can exploit it over a network to elevate their privileges within the service. CVSS score: 10.0.
CVE-2026-83711 affects Microsoft Azure Active Directory B2C. The flaw is an authorisation bypass through a user-controlled key. Again: unauthenticated, network-exploitable, privilege escalation. CVSS score: 10.0.
Same day, a third Microsoft flaw appeared: CVE-2026-62916, an authentication bypass in Microsoft Entra ID scoring CVSS 9.1. Entra ID is the identity platform underpinning most Microsoft 365 environments.
Three identity and access flaws in Microsoft’s cloud stack, published simultaneously. One of them is a perfect ten. Two of them are perfect tens.
Why This Matters to a Business Running Microsoft 365
The vendor response will tell you these are cloud-side issues and that patches are Microsoft’s responsibility. That is technically accurate. It is also incomplete.
Here is what the vendor response will not tell you.
Azure Active Directory B2C is the identity layer that many SaaS applications and line-of-business tools use to handle customer and employee authentication. If your business uses any cloud application that delegates its login to Microsoft’s infrastructure, CVE-2026-83711 sits in that authentication chain.
Azure AI Language is the engine behind a growing number of productivity tools, including document analysis, automated customer service, and compliance checking tools that smaller organisations have been sold as affordable AI. If your business has adopted any of these in the last two years, you are on Azure AI Language whether you know it or not.
Microsoft Entra ID is your Microsoft 365 login. Full stop.
The fixes are Microsoft’s to deploy. But verification is yours. Your managed service provider should be confirming, in writing, that your cloud environment has been assessed in light of these vulnerabilities and that your tenant configuration is not creating additional exposure.
If your MSP cannot tell you what steps they have taken in response to three simultaneous high-severity Microsoft cloud vulnerabilities, that is information worth having.
The WordPress Problem That Is Not Waiting
Separate from the Microsoft story, and arguably more immediately pressing for businesses with a web presence: attackers are actively exploiting a critical file upload vulnerability in Elementor Pro (CVE-2026-32475).
Elementor Pro is a paid WordPress page builder plugin used on an estimated six million websites. The vulnerability allows an attacker to upload malicious PHP files to the web server and execute them remotely. The practical outcome: backdoor installation, rogue administrator account creation, and full site compromise.
A security update was released on 19 August 2026. Active exploitation was confirmed by Wordfence in early September.
The gap between patch availability and attacker activity is two weeks. If your WordPress site is running Elementor Pro and has not been updated since mid-August, it is currently being scanned for this vulnerability by automated tooling. The question is not whether attackers are looking. The question is whether they have found yours yet.
This is not theoretical. The exploit has been publicly disclosed. The attack surface is enormous.
How This Gives You an Edge
Most small business owners will hear nothing about CVE-2026-70352, CVE-2026-83711, or CVE-2026-32475 from their IT provider unless they ask. That gap is an opportunity.
Businesses that actively track their exposure to critical vulnerabilities and can demonstrate that their cloud environment is monitored and maintained are increasingly distinguishable from those that cannot. In procurement processes, in insurance renewals, in client due diligence questionnaires: the question is no longer just “do you have a firewall.” It is “how do you know your cloud provider’s vulnerabilities are not creating risk in your environment.”
Asking your MSP for a written response to this week’s Microsoft advisories is a low-cost action that produces a useful signal. Either they respond promptly with a clear answer, which tells you the relationship is working, or they do not, which tells you something equally valuable.
For businesses with a WordPress website, verifying that your site is running on current plugin versions and that someone is responsible for applying security updates is a basic due diligence step that separates organisations with a maintenance posture from those running on hope.
Making the Business Case
Three points worth raising with whoever controls your technology budget.
Cloud services create dependencies you cannot patch yourself. Two of this week’s critical vulnerabilities are in Microsoft’s infrastructure. You cannot fix them. You can only verify that your configuration does not amplify them, and that your identity layer has appropriate controls applied. That requires someone with the skills and access to check. If that person is your MSP, they need to be demonstrably on top of vendor advisories.
The cost of an Elementor Pro update is approximately nothing. The cost of a compromised website is not. A successfully exploited WordPress site can be used to deliver malware to your visitors, steal form submissions including customer enquiries and payment data, host phishing pages targeting other organisations, and expose you to ICO enforcement action under UK GDPR. The update takes minutes. The incident response does not.
Three Microsoft cloud vulnerabilities in one day is a pattern worth noting. It is not evidence of a conspiracy. It is evidence that complex cloud infrastructure produces a continuous stream of high-severity findings, and that relying on a single vendor for identity, productivity, and AI tooling concentrates that risk. Diversity of vendor relationships and a clear picture of what your business actually depends on are both worth having.
What to Do Before Friday
1. Check your WordPress site’s plugin versions today. Log into your WordPress admin panel and navigate to Plugins. If Elementor Pro is installed, confirm it is running version 3.27.3 or later. If it is not, update it immediately. If you do not have access to do this, contact whoever manages your website and request written confirmation that the update has been applied.
2. Ask your MSP one direct question. “In light of CVE-2026-70352, CVE-2026-83711, and CVE-2026-62916 published on 3 September, what steps have you taken to assess our Microsoft cloud environment?” The question is specific. A competent MSP should be able to answer it. Document the response.
3. Confirm MFA is active on every Microsoft 365 account. The authentication bypass vulnerabilities published this week are partly mitigated by strong multi-factor authentication (MFA) applied consistently. Log into your Microsoft 365 admin centre and check that MFA is enforced for all users, including administrators. No exceptions for senior staff who find it inconvenient.
4. Review who has administrator access to your Microsoft tenancy. Privilege escalation vulnerabilities are most damaging when an attacker can reach an account that already has broad permissions. Audit your admin accounts. Remove any that belong to former employees, contractors, or accounts that exist for historical reasons. Fewer privileged accounts means a smaller blast radius.
5. If you use any Azure AI-based tools, check with the vendor. If you have adopted AI-assisted document processing, automated customer communications, or any compliance tooling in the last two years, ask the vendor directly whether their product uses Azure AI Language and what their assessment of CVE-2026-70352 is for their service. A vendor who cannot answer that question within 24 hours is a vendor worth reconsidering.
Before you go: follow the show wherever you listen, and if today’s brief was useful, leave a rating or a review. It genuinely helps. Drop a comment with your thoughts, particularly if your MSP responds to that question with something worth sharing. And if you know a business owner who should be across this, send it to them. They can deal with it now, or deal with the consequences later.