{"id":265643,"date":"2026-08-24T23:08:10","date_gmt":"2026-08-24T23:08:10","guid":{"rendered":"https:\/\/www.europesays.com\/ch-de\/265643\/"},"modified":"2026-08-24T23:08:10","modified_gmt":"2026-08-24T23:08:10","slug":"microsoft-stopft-zahlreiche-cloud-schwachstellen-heise-online","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ch-de\/265643\/","title":{"rendered":"Microsoft stopft zahlreiche Cloud-Schwachstellen | heise online"},"content":{"rendered":"<p>    close notice<\/p>\n<p class=\"notice-banner__text a-u-mb-0\">\n      This article is also available in<br \/>\n        <a href=\"https:\/\/www.heise.de\/en\/news\/Microsoft-plugs-numerous-cloud-vulnerabilities-11423162.html\" class=\"notice-banner__link a-u-inline-link\" rel=\"nofollow noopener\" target=\"_blank\">English<\/a>.<\/p>\n<p>      It was translated with technical assistance and editorially reviewed before publication.\n    <\/p>\n<p class=\"notice-banner__link a-u-mb-0\">\n    Don\u2019t show this again.\n<\/p>\n<p>Die gute Nachricht vorweg: Da es um Cloud-Produkte von Microsoft geht, m\u00fcssen IT-Verantwortliche nicht aktiv werden, das Unternehmen hat die Sicherheitsl\u00fccken bereits serverseitig gepatcht. Berichte \u00fcber bereits attackierte L\u00fccken etwa in Microsofts Entra ID waren jedoch verfr\u00fcht, Microsoft hat die fehlerhafte Angabe inzwischen korrigiert.<\/p>\n<p>        Weiterlesen nach der Anzeige<\/p>\n<p>Die Schwachstellen hat Microsoft am vergangenen Freitag ver\u00f6ffentlicht. Zur kritischen Sicherheitsl\u00fccke CVE-2026-69836 in Entra ID schrieb Microsoft zun\u00e4chst, dass sie bereits attackiert wurde (Exploited: Yes). Der Versionsverlauf zeigt auf, dass Microsoft im Laufe des Freitags das schlie\u00dflich korrigiert und den Eintrag auf \u201eNo\u201c gesetzt hat \u2013 die L\u00fccke wurde doch nicht in freier Wildbahn angegriffen. Die Liste der in der Nacht zum Freitag ver\u00f6ffentlichten und geschlossenen L\u00fccken in den Azure-Diensten ist etwas l\u00e4nger:<\/p>\n<p>Microsoft Entra ID Remote Code Execution Vulnerability (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69836\" rel=\"external noopener nofollow\" target=\"_blank\">CVE-2026-69836<\/a>, CVSS 10.0, Risiko \u201ekritisch\u201c)Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-65770\" rel=\"external noopener nofollow\" target=\"_blank\">CVE-2026-65770<\/a>, CVSS 10.0, Risiko \u201ekritisch\u201c)Azure Arc Elevation of Privilege Vulnerability (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69555\" rel=\"external noopener nofollow\" target=\"_blank\">CVE-2026-69555<\/a>, CVSS 10.0, Risiko \u201ekritisch\u201c)Azure SQL Database Elevation of Privilege Vulnerability (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69502\" rel=\"external noopener nofollow\" target=\"_blank\">CVE-2026-69502<\/a>, CVSS 10.0, Risiko \u201ekritisch\u201c)Azure Arc Elevation of Privilege Vulnerability (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-65816\" rel=\"external noopener nofollow\" target=\"_blank\">CVE-2026-65816<\/a>, CVSS 10.0, Risiko \u201ekritisch\u201c)Microsoft Exchange Online Elevation of Privilege Vulnerability (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-65801\" rel=\"external noopener nofollow\" target=\"_blank\">CVE-2026-65801<\/a>, CVSS 10.0, Risiko \u201ekritisch\u201c)Microsoft Entra ID Elevation of Privilege Vulnerability (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69851\" rel=\"external noopener nofollow\" target=\"_blank\">CVE-2026-69851<\/a>, CVSS 9.9, Risiko \u201ekritisch\u201c)Azure SQL Database Elevation of Privilege Vulnerability (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-68789\" rel=\"external noopener nofollow\" target=\"_blank\">CVE-2026-68789<\/a>, CVSS 9.9, Risiko \u201ekritisch\u201c)Azure SQL Database Elevation of Privilege Vulnerability (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-68782\" rel=\"external noopener nofollow\" target=\"_blank\">CVE-2026-68782<\/a>, CVSS 9.9, Risiko \u201ekritisch\u201c)Azure Logic Apps Elevation of Privilege Vulnerability (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69400\" rel=\"external noopener nofollow\" target=\"_blank\">CVE-2026-69400<\/a>, CVSS 9.6, Risiko \u201ekritisch\u201c)Azure Data Factory Elevation of Privilege Vulnerability (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-62834\" rel=\"external noopener nofollow\" target=\"_blank\">CVE-2026-62834<\/a>, CVSS 9.3, Risiko \u201ekritisch\u201c)Azure SQL Database Elevation of Privilege Vulnerability (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-66309\" rel=\"external noopener nofollow\" target=\"_blank\">CVE-2026-66309<\/a>, CVSS 9.1, Risiko \u201ekritisch\u201c)Microsoft Partner Center Information Disclosure Vulnerability (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69558\" rel=\"external noopener nofollow\" target=\"_blank\">CVE-2026-69558<\/a>, CVSS 8.6, Risiko \u201ehoch\u201c)Azure Stack HCI Information Disclosure Vulnerability (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69519\" rel=\"external noopener nofollow\" target=\"_blank\">CVE-2026-69519<\/a>, CVSS 8.6, Risiko \u201ehoch\u201c)Azure Data Factory Information Disclosure Vulnerability (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-66800\" rel=\"external noopener nofollow\" target=\"_blank\">CVE-2026-66800<\/a>, CVSS 8.6, Risiko \u201ehoch\u201c)Azure Virtual Machines Elevation of Privilege Vulnerability (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69543\" rel=\"external noopener nofollow\" target=\"_blank\">CVE-2026-69543<\/a>, CVSS 8.5, Risiko \u201ehoch\u201c)Azure Data Manager for Energy Remote Code Execution Vulnerability (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69419\" rel=\"external noopener nofollow\" target=\"_blank\">CVE-2026-69419<\/a>, CVSS 8.5, Risiko \u201ehoch\u201c)Microsoft Copilot in Azure Information Disclosure Vulnerability (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-69855\" rel=\"external noopener nofollow\" target=\"_blank\">CVE-2026-69855<\/a>, CVSS 7.7, Risiko \u201ehoch\u201c)<\/p>\n<p>Doch (noch) keine Cyberangriffe<\/p>\n<p>Zu keiner der L\u00fccken schreibt Microsoft (mehr), dass sie bereits von b\u00f6sartigen Akteuren angegriffen wurden. Die Menge an kritischen L\u00fccken teils mit H\u00f6chstwertung des Risikos von CVSS 10.0 etwa in besonders sensiblen Diensten wie Microsoft Exchange Online ist dennoch \u00fcberraschend.<\/p>\n<p>Zuletzt wurde vergangenen Donnerstag bekannt, dass <a href=\"https:\/\/www.heise.de\/thema\/Microsoft\" rel=\"nofollow noopener\" target=\"_blank\">Microsoft<\/a> auf seinen Servern Sicherheitsl\u00fccken geschlossen hat. Da ging es jedoch um den KI-Assistenten Copilot. Der hatte vor der Korrektur auf Nachfrage <a href=\"https:\/\/www.heise.de\/news\/Sicherheitsluecke-in-Microsoft-365-Copilot-KI-verraet-eigene-Schutzmechanismen-11420618.html\" rel=\"nofollow noopener\" target=\"_blank\">preisgegeben, \u00fcber welche Schwachstellen er angreifbar<\/a> ist.<\/p>\n<p>(<a class=\"redakteurskuerzel__link\" href=\"https:\/\/www.heise.de\/news\/mailto:dmk@heise.de\" title=\"Dirk Knop\" rel=\"nofollow noopener\" target=\"_blank\">dmk<\/a>)<\/p>\n<p>\n      Dieser Link ist leider nicht mehr g\u00fcltig.\n    <\/p>\n<p>Links zu verschenkten Artikeln werden ung\u00fcltig,<br \/>\n      wenn diese \u00e4lter als 7\u00a0Tage sind oder zu oft aufgerufen wurden.\n    <\/p>\n<p>Sie ben\u00f6tigen ein heise+ Paket, um diesen Artikel zu lesen. Jetzt eine Woche unverbindlich testen \u2013 ohne Verpflichtung!<\/p>\n","protected":false},"excerpt":{"rendered":"close notice This article is also available in English. It was translated with technical assistance and editorially reviewed&hellip;\n","protected":false},"author":2,"featured_media":265644,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[14],"tags":[57,46,16634,52,51,622,53,56,560,30979,45,557,2473,44,55,54,2416],"class_list":["post-265643","post","type-post","status-publish","format-standard","has-post-thumbnail","category-unternehmen-maerkte","tag-business","tag-ch","tag-cloud-computing","tag-companies","tag-companies-markets","tag-it","tag-markets","tag-maerkte","tag-microsoft","tag-microsoft-azure","tag-schweiz","tag-security","tag-sicherheitsluecken","tag-switzerland","tag-unternehmen","tag-unternehmen-maerkte","tag-updates"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@ch_de\/117152998398181264","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ch-de\/wp-json\/wp\/v2\/posts\/265643","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ch-de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ch-de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ch-de\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ch-de\/wp-json\/wp\/v2\/comments?post=265643"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ch-de\/wp-json\/wp\/v2\/posts\/265643\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ch-de\/wp-json\/wp\/v2\/media\/265644"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ch-de\/wp-json\/wp\/v2\/media?parent=265643"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ch-de\/wp-json\/wp\/v2\/categories?post=265643"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ch-de\/wp-json\/wp\/v2\/tags?post=265643"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}