Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Microsoft addressed 18 critical vulnerabilities across its cloud services and AI products, including Copilot, with many discovered by external researchers. While some flaws were exploited internally, all fixes were implemented on the server side, requiring no action from users, except for a Windows update to address a separate privilege escalation vulnerability.
Microsoft released a substantial update this week, addressing 18 critical vulnerabilities affecting its Azure cloud offerings and Copilot AI products. The majority of these vulnerabilities were related to privilege escalation, impacting services such as Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Billing, Azure HorizonDB, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Microsoft Dataverse, and Microsoft 365 Copilot. Several information disclosure flaws were also patched within Copilot and related products. A single spoofing vulnerability was addressed in Azure Portal.
Microsoft rated all 18 vulnerabilities as critical, though some had CVSS scores indicating high or medium severity. Many of these flaws were identified by external researchers, reflecting a trend of increased vulnerability discovery driven by the growing adoption of advanced AI technologies within Microsoft’s products. Notably, a separate privilege escalation vulnerability affecting Windows (CVE-2026-85921) requires user action to update Windows to mitigate the risk of exploitation, although Microsoft believes exploitation is unlikely.
Microsoft’s latest Patch Tuesday update represents a record number of fixes, totaling 970 vulnerabilities across its entire product portfolio. This highlights the ongoing commitment to security and proactive vulnerability management within the company.