BeyondTrust Microsoft Vulnerabilities Report 2026: Critical Flaws More Than Double as Elevation of Privilege Dominates (CVE-2025-55241, CVE-2025-62557, CVE-2025-62554) — Threadlinqs Intelligence
As of 2026-07-02, BeyondTrust Microsoft Vulnerabilities Report 2026: Critical Flaws More Than Double as Elevation of Privilege Dominates (CVE-2025-55241, CVE-2025-62557, CVE-2025-62554) is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1060 · Severity: HIGH · CVSS: 10 · Status: TRACKING · Category: VULNERABILITY
BeyondTrust's 13th annual Microsoft Vulnerabilities Report shows total Microsoft CVEs fell 6% YoY (1,360 to 1,273) while critical-severity vulnerabilities more than doubled (78 to 157, a 101%
BeyondTrust published the 13th edition of its annual Microsoft Vulnerabilities Report on 2026-07-02, analyzing Microsoft's full-year 2025 CVE disclosures. While the raw count of Microsoft vulnerabilities declined 6% year-over-year (1,360 in 2024 to 1,273 in 2025), the report's central finding is that risk did not decrease -- it concentrated. Critical-severity vulnerabilities more than doubled, rising 101% from 78 to 157. Under the newer CVSS v4 scoring methodology, critical-rated flaws also rose from 39 to 42. The concentration of risk is most acute in cloud and productivity surfaces: Microsoft Azure and Dynamics 365 saw critical vulnerabilities increase 9x, from 4 in 2024 to 37 in 2025, and Microsoft Office's critical vulnerability count rose roughly 10x, from 3 in 2024 to 31 in 2025 (with total Office CVEs more than tripling from 47 to 157). Windows and Windows Server remain the largest raw-volume products (612 and 780 CVEs respectively, with 36 and 50 rated critical), while Microsoft Edge fell 83% year-over-year to 50 CVEs and zero rated critical. By vulnerability category, Elevation of Privilege (EoP) is the dominant class for the fourth consecutive year, accounting for 509 CVEs (40% of all disclosures), followed by Remote Code Execution at 373 CVEs (29%) and Information Disclosure at 175 CVEs (up 73% from 101 in 2024). BeyondTrust's analysis, quoting security researcher Sami Laiho ('The true risk in modern environments isn't the presence of vulnerabilities -- it's the presence of unnecessary privilege'), frames the trend as validation that privilege -- not raw bug count -- is now the primary attack surface in Microsoft environments. The report is illustrated by two headline 2025 vulnerabilities that exemplify the EoP and RCE trend lines documented in the aggregate data. CVE-2025-55241 is a CVSS 10.0 (Microsoft CNA scoring; NVD scores 9.8) Elevation of Privilege vulnerability in Microsoft Entra ID (CWE-287, Improper Authentication), discovered by independent researcher Dirk-Jan Mollema and reported to MSRC on 2025-07-14. The flaw exploited an undocumented 'Actor token' mechanism used for internal Microsoft service-to-service communication: Actor tokens are valid for 24 hours, are not logged when issued or used, cannot be revoked, and bypass Conditional Access policies entirely. These tokens are wrapped in an unsigned impersonation JWT, and the legacy Azure AD Graph API (graph.windows.net) failed to validate that the impersonation JWT's tenant-ID claim matched the tenant actually being queried. An attacker able to obtain an Actor token from any tenant (including a self-owned trial tenant) could therefore forge an impersonation token naming an arbitrary target tenant ID and an arbitrary internal user identifier (netId), and the target tenant's Azure AD Graph API would accept it -- effectively allowing impersonation of any identity in any Entra ID tenant, including Global Administrators, with no authentication challenge, no MFA prompt, and no audit trail for read operations. Attackers could obtain valid netId values via incremental brute-forcing, extraction from previously leaked/expired tokens, or via B2B guest-user attributes exposed through cross-tenant trust relationships -- meaning any organization that accepted an external guest invitation became a potential pivot point into unrelated tenants, including theoretically Microsoft's own corporate tenant. Microsoft deployed a global production fix on 2025-07-17 (three days after report) and a secondary mitigation on 2025-08-06 blocking Actor-token issuance via Service Principal credentials for the Azure AD Graph endpoint; the CVE was formally published 2025-09-04. No customer action was required and no in-the-wild exploitation was confirmed prior to the fix, though CISA has since flagged the CVE as having public proof-of-concept / technical exploitation detail available (Mollema's writeup includes attack methodology sufficient to reconstruct the technique). CVE-2025-62557 (C
Weaknesses (CWE)
CWE-287, CWE-416, CWE-843
Target sectors: government administration, finance, health, technology, education, manufacturing, critical-infrastructure, cross-industry-microsoft-tenants
Target regions: Global, North America, Europe
Detections & IOCs
As of 2026-08-24, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2025-55241, CVE-2025-62557, CVE-2025-62554, T1199, T1566, T1203, T1098.003, T1068, T1078.004, T1548, T1078.004, T1685.002, T1556.006