www.securityweek.com 18 Sept 2026, 10:57 UTC

Microsoft Patches 18 Critical Azure and Copilot Flaws, but One Windows Bug Requires Action

Microsoft Patches 18 Critical Azure and Copilot Flaws, but One Windows Bug Requires Action
CyberSIXT Evidence Panel
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

MICROSOFT has released patches for 18 vulnerabilities affecting its Azure cloud services and Copilot-branded artificial intelligence products. Elevation-of-privilege flaws accounted for most of the issues and affected Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Billing, Azure HorizonDB, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Microsoft Dataverse and Microsoft 365 Copilot.

Microsoft also fixed information-disclosure vulnerabilities in Copilot, Microsoft 365 Copilot, Microsoft 365 Copilot Business Chat and Azure Machine Learning, along with a spoofing vulnerability in Azure Portal. The company rated all 18 vulnerabilities as critical, although their CVSS scores put some at high or medium severity. Several were found internally, while others were reported by external researchers.

None of the vulnerabilities has been flagged as exploited. Microsoft said all the fixes were implemented server-side, so customers do not need to take action. Separately, Microsoft disclosed a Windows privilege-escalation vulnerability, CVE-2026-85921, which users must patch locally; the company considers exploitation of that flaw “less likely”.

View full article

Article by CyberSIXT