Top 5

  1. CVE-2026-54411: Linux-PAM Timing Side-Channel Leaks Plaintext Passwords — A timing discrepancy in pam_userdb’s plaintext comparison path lets a local or network-adjacent attacker recover plaintext passwords through timing analysis alone, when pam_userdb is configured with crypt=none or an unrecognized crypt method. If any Linux workload in your environment uses pam_userdb with plaintext credential storage, fix the configuration now — this requires no exploit code, just patience.

  2. CVE-2026-12012: Chromium Use-After-Free Patched in Edge — A use-after-free vulnerability in the Chromium network stack has been patched in the Edge release train. Confirm your managed fleet is actually current — verify via Intune compliance or Defender for Endpoint software inventory rather than assuming auto-update has caught everyone.

  3. Purview Data Protection Extended to AWS Bedrock Agents — Purview can now act as the policy engine for AI workloads running on AWS Bedrock, enforcing sensitivity labels and DLP across cloud boundaries. If you run hybrid AI — M365 data plus AWS inference — this closes a real cross-cloud governance gap. Map your Bedrock agent data flows now.

  4. M365 Apps Cloud Update: Enhanced Rollout Waves — Cloud Update for M365 Apps is dropping the three-wave limit and adding Entra ID group-based waves with configurable inter-wave delays. Preview is live now with GA targeted for June — worth restructuring your phased deployment plan to take advantage of the added granularity.

  5. ASSERT: Microsoft’s Open-Source Framework for Agent Evaluation — ASSERT converts natural-language behavioral specs into executable evaluations for AI models and agents, and it’s open source. If you’re building or governing agents, this gives you a structured way to turn a requirements doc into automated test coverage — pairs well with Copilot Studio’s native evaluation tooling.


Identity

  • M365 Apps Cloud Update: Enhanced Rollout Waves [Preview] — Cloud Update for M365 Apps is moving out of the three-wave limit, adding support for more Entra ID group-based waves and configurable inter-wave delays. Preview is live in May, GA targets June — review your current wave configuration and plan to restructure phased deployments to take advantage of the additional granularity.

  • CVE-2026-54411: Linux-PAM Timing Side-Channel in pam_userdb [GA] — A timing discrepancy in pam_userdb’s plaintext comparison path allows a local or network-adjacent attacker to recover plaintext passwords when pam_userdb is configured with crypt=none or an unrecognized crypt method. If any Linux workloads in your environment use pam_userdb with plaintext credential storage, remediate the configuration immediately — this is exploitable by timing analysis alone.


Apps

  • What’s New in Microsoft 365 Copilot — April 2026 [GA] — April’s Copilot wave includes Copilot Notebooks updates, Plan mode and Python support in Excel, image editing and public website grounding in PowerPoint, and Claude model availability in Copilot Chat. Review the full changelog and update your end-user enablement materials — several features require user awareness to drive adoption and a few may warrant communication on data handling (e.g., public website grounding).

  • Power Fx: User Defined Types Generally Available [GA] — User Defined Types are now on by default for new Power Apps as of Studio version 3.26044, with opt-in for existing apps via Settings > Updates > New. Review existing apps before enabling UDTs — test for behavioral changes in complex formulas before rolling out to production apps.


Data

  • Extend Microsoft Purview Data Protection to AWS Bedrock Agents [GA] — Purview can now act as the central policy engine for AI workloads running on AWS Bedrock, enabling consistent sensitivity label enforcement and DLP controls across cloud boundaries. If your org runs hybrid AI (M365 data + AWS inference), this closes the cross-cloud governance gap — map your Bedrock agent data flows and apply Purview policies now.

  • Purview Data Security Investigations: Pre-Built Search Templates [GA] — Pre-configured search templates for common data security investigation scenarios are GA in June 2026, reducing investigation setup from manual query-building to a few clicks. Update your IR playbooks to reference the available templates — this meaningfully reduces mean time to scope for data security incidents.

  • Bulk Deletion in Microsoft Dataverse [GA] — Native Dataverse bulk deletion capabilities have been expanded, giving admins better tools to manage storage consumption from accumulated data at scale. Audit your high-volume Dataverse environments for stale records and schedule bulk deletion jobs to reclaim storage before it affects capacity thresholds.


Network

  • CVE-2026-12012: Chromium Use-After-Free in Edge [GA] — A Chromium use-after-free vulnerability affecting the network stack has been patched in the upstream Chromium release ingested by Microsoft Edge. Validate your Edge update rings are current — managed devices should be verified via Intune compliance or Defender for Endpoint’s software inventory within the next patch cycle.

Visibility & Automation

  • ASSERT: Open-Source Framework for Agent Evaluation [GA] — Microsoft’s ASSERT framework converts natural language behavioral specifications into executable evaluations for AI models and agents, published as open source. If your team is building agents, ASSERT gives you a structured, repeatable way to convert your behavioral requirements doc into automated test coverage — worth integrating alongside Copilot Studio’s native evaluation tooling.

Action Required

  • Exchange 2016/2019 ESU Period 2 — Immediate Enrollment Required [GA] — Deadline: May 2026 start / April 2027 end for Period 2. If you are running Exchange 2016 or 2019 on-premises and Period 1 ESU has lapsed, you are currently unprotected. Enroll in Period 2 ESU immediately or commit to an accelerated migration to Exchange SE — running unpatched on-premises Exchange is not an acceptable security posture.

  • CVE-2026-12012: Patch Edge Now [GA] — Action within current patch cycle. A use-after-free vulnerability in the Chromium network stack affects Edge — verify all managed devices are running the latest Edge build via Intune compliance policy or Defender for Endpoint software inventory. Don’t rely on auto-update alone; confirm coverage across your managed fleet.

  • CVE-2026-54411: Audit pam_userdb Configurations on Linux Workloads [GA] — Action immediately if applicable. Linux-PAM through 1.7.2 with crypt=none or no crypt= argument leaks plaintext passwords via timing analysis. Audit all Linux systems in your environment for pam_userdb usage, switch to a hashed crypt method or remove plaintext credential storage, and update PAM packages when vendor patches are available.

  • Intune Advanced Suite Bundling — CY26 Q3 Rollout Incoming [GA] — 30-day Message Center notice precedes tenant enablement. Advanced Intune Suite capabilities are being added to broader M365 plans starting CY26 Q3. Review your licensing, determine whether newly bundled capabilities change your existing Intune Suite procurement, and plan for any configuration or policy changes triggered by new feature availability in your tenant.

  • Computer-Using Agents: Establish Governance Before Business Unit Deployment [GA] — 30-day governance window. Computer-using agents are GA and accessible to makers in Copilot Studio — without proactive governance, business units will deploy agents with broad UI access and no audit controls. Define and publish agent governance policy covering identity scope, data handling, audit logging requirements, and approval workflows before the first production agent goes live in your tenant.