EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

Microsoft security advisory – August 2026 monthly rollup (AV26-804) – Update 4

Official source
EudorIA operational summary

What it means

Priority 85/100

Microsoft ha rilasciato un aggiornamento di sicurezza nel mese di agosto 2026 che riguarda diversi prodotti, tra cui .NET, Microsoft 365, SharePoint e Dynamics 365. Alcune vulnerabilità sono state riconosciute come sfruttate in ambiente reale, tra cui CVE-2026-33824 e CVE-2026-55040. L'aggiornamento include patch per mitigare tali rischi.

Why it matters

Le vulnerabilità colpite potrebbero consentire agli attaccanti di eseguire codice non autorizzato, compromettere la sicurezza dei dati e compromettere la disponibilità dei servizi. Per le PMI italiane, la mancanza di aggiornamenti potrebbe portare a interruzioni operative e perdite di dati sensibili.

Potential operational benefits

  • Riduzione della superficie esposta alle vulnerabilità
  • Miglioramento della rilevazione e risposta agli attacchi
  • Protezione dei dati sensibili e della disponibilità dei servizi
  • Riduzione del rischio di interruzioni operative
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementSegmentazione di reteMonitoraggio / SIEMEDR / XDRBackup & DR
AudienceITSOCCISO
Information centre

Translation in progress

Canadian Centre for Cyber Security

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Serial Number: AV26-804 Date: August 11, 2026 Updated: September 25, 2026 As of August 11, 2026, Microsoft is affected by vulnerabilities in the following products: .NET 10.0 installed on Linux .NET 10.0 installed on Mac OS .NET 10.0 installed on Windows .NET 8.0 installed on Linux .NET 8.0 installed on Mac OS .NET 8.0 installed on Windows .NET 9.0 installed on Linux .NET 9.0 installed on Mac OS .NET 9.0 installed on Windows App Installer Application Insights Profiler Azure Active Directory Azure Confidential Ledger Azure CycleCloud Azure Kubernetes Service Azure Logic Apps Azure Monitor Agent Linux Extension Azure SQL Database Azure SQL Managed Instance Azure SRE Agent Azure Service Bus Azure Storage Explorer Microsoft .NET Framework 3.5 Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 3.5 AND 4.7.2 Microsoft .NET Framework 3.5 AND 4.8 Microsoft .NET Framework 3.5 AND 4.8.1 Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 4.8 Microsoft .NET Framework 4.8.1 Microsoft 365 Admin Center Microsoft 365 Apps for Enterprise Microsoft Access 2016 Microsoft Defender for Endpoint for Mac Microsoft Dynamics 365 (on-premises) Microsoft Dynamics 365 Business Central 2024 Microsoft Dynamics 365 Business Central 2026 Microsoft Dynamics 365 Business Central Release Wave 1 2025 Microsoft Dynamics 365 Business Central Release Wave 2 2025 Microsoft Entra Connect Microsoft Entra ID Microsoft Entra Provisioning Service Microsoft Excel 2016 Microsoft Exchange Server 2016 Microsoft Exchange Server 2019 Microsoft Exchange Server Subscription Edition RTM Microsoft Office 2016 Microsoft Office 2019 Microsoft Office 365 for Mac Microsoft Office LTSC 2021 Microsoft Office LTSC 2024 Microsoft Office LTSC for Mac 2021 Microsoft Office LTSC for Ma

Source
Canadian Centre for Cyber Security (Canada)
Publishing entity
Canadian Centre for Cyber Security
Entity type
National CSIRT
Area
North America · CA
Original language
en · translation in preparation
Publication
25/09/2026 17:55
MITRE ATT&CK
T1190, T1078, T1486
Stated country
CA
Open the original source