MICROSOFT has released patches for 18 vulnerabilities affecting its Azure cloud services and Copilot-branded artificial intelligence products. Elevation-of-privilege flaws accounted for most of the issues and affected Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Billing, Azure HorizonDB, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Microsoft Dataverse and Microsoft 365 Copilot.
Microsoft also fixed information-disclosure vulnerabilities in Copilot, Microsoft 365 Copilot, Microsoft 365 Copilot Business Chat and Azure Machine Learning, along with a spoofing vulnerability in Azure Portal. The company rated all 18 vulnerabilities as critical, although their CVSS scores put some at high or medium severity. Several were found internally, while others were reported by external researchers.
None of the vulnerabilities has been flagged as exploited. Microsoft said all the fixes were implemented server-side, so customers do not need to take action. Separately, Microsoft disclosed a Windows privilege-escalation vulnerability, CVE-2026-85921, which users must patch locally; the company considers exploitation of that flaw “less likely”.