
Microsoft
Global software and cloud giant; Azure, M365, Intune; DMA probe and US cloud sovereignty risk.
SharePoint remained under active exploitation through July 2026, the latest in a run of Microsoft patch emergencies that began with a 17-year-old Office remote-code flaw returning to the exploited-vulnerabilities list in April.
Last refreshed: 4 August 2026 · Appears in 5 active topics
Microsoft admitted to the French Senate it cannot guarantee French data stays in France: what does that mean for its European cloud business?
Timeline for Microsoft
Mentioned in: Marking code draws 190, none of them TV
Media's AI PivotReported quarterly capex and revised its calendar-2026 capex estimate to ~$175bn
Data Centres: Boom and Backlash: The big four's combined capex holds near $732bnDublin slips to 15% as growth heads north
Data Centres: Boom and BacklashMentioned in: Google fined €890m four days before EU deadline
European Tech SovereigntyMentioned in: Hotel WiFi steers guests to fake logins
Cybersecurity: Threats and DefencesBackground
Microsoft, founded by Bill Gates and Paul Allen in 1975, is among the world's most valuable companies by market capitalisation. Its Azure cloud platform competes with Amazon Web Services and Google Cloud for enterprise and AI workloads; GitHub Copilot is the most widely adopted AI coding assistant, and Microsoft 365 Copilot embeds generative AI across its Office suite.
The European Commission opened a Digital Markets Act cloud-gatekeeper probe against Azure in October 2025, alongside a parallel probe of AWS . Microsoft has told the French Senate it cannot guarantee French customer data on Azure would never be disclosed under US legal orders, the CLOUD Act exposure that leaves it ineligible for the EU's top sovereign-cloud procurement tier.
Its enterprise ubiquity across government and corporate networks makes it a persistent target: state-linked hacking groups and criminal actors alike probe its products for footholds, and its cloud and productivity suites now underpin AI deployment across most large organisations, which raises the stakes of every vulnerability and every data-sovereignty question it faces.
Microsoft's software stays under active fire
A 17-year-old Office remote-code-execution flaw returned to the US government's Known Exploited Vulnerabilities list on 14 April 2026 , the same week Russia's GRU was found hijacking home routers to harvest Microsoft 365 login credentials . SharePoint flaws kept the pressure on through the summer, with a patch deadline on 1 July and active exploitation still logged on 22 July .
The repeated cycle, an old bug resurfacing, a nation-state credential campaign, then a live SharePoint exploit still unresolved three weeks after its patch Deadline, illustrates why Microsoft's enterprise ubiquity is also its largest liability: its software sits deep enough in government and corporate networks that any flaw becomes a standing national-security concern rather than a routine bug.
A Wisconsin lawsuit targets Microsoft's water use
Microsoft's Mount Pleasant, Wisconsin data-centre campus faces litigation over roughly 8 million gallons of water use, part of a wider legal and permitting dispute over the site's local resource impact .
The case sits alongside a separate setback in Kenya, where the planned $1bn Olkaria data-centre campus with G42 was halted in May 2026 over grid capacity and financing terms . Together they show Microsoft's AI-driven data-centre build-out running into the same physical constraints, water, power and local consent, on two different continents.