Trust & Security
Microsoft’s Two-Track Patch Tuesday: Cloud Identity Flaws Fixed Before Disclosure, Windows Still Catching Up
The September 8 batch covers 70 CVEs including Windows Secure Kernel Mode and VBS vulnerabilities. But the most critical identity flaws—Azure AD B2C and Entra ID at CVSS 10.0—were silently fixed five days earlier, all server-side, no customer action required.
◆ Heath Callahan