All findings

CVE-2026-50351 + 8 more critical

XBreach's Microsoft credit wave spans nine Windows and Azure CVEs

MSRC credits XBreach across nine public CVEs spanning Windows, Edge, Azure AI Search, CycleCloud, App Service, and Confidential Ledger.

Bug class
Privilege escalation, RCE, security-feature bypass, and information disclosure
Affected codebase
Microsoft Windows, Edge, Azure AI Search, Azure CycleCloud, Azure App Service, and Azure Confidential Ledger
Credited system
XBREACH
Disclosed
August 11, 2026
Attribution
Self-reported attribution
Severity
critical
Source status: MSRC corroborates all nine accepted vulnerability records and credits XBreach. XBreach's own platform material supplies the autonomous AI-workflow context, so the system attribution remains self-reported. The cluster uses the maximum upstream score, including a CVSS 10 Azure App Service issue.

Summary

The nine records cover Windows Audio Compression Manager, Edge, Azure AI Search, several Azure CycleCloud boundaries, Azure App Service on Azure Stack Hub, and Azure Confidential Ledger. Upstream scores range from medium to a CVSS 10 privilege-escalation record.

The affected products and fixes are independently public. The statement that these organization credits came from XBreach’s autonomous platform remains an operator claim, so the attribution label is self-reported.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.