Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Microsoft patched 18 elevation-of-privilege and information-disclosure vulnerabilities across Azure and Copilot products; all fixed server-side with no exploitation observed.
Microsoft on Thursday released patches for 18 vulnerabilities spanning its Azure cloud portfolio and Copilot-branded AI products, with elevation-of-privilege flaws affecting Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Dataverse, and Microsoft 365 Copilot, among others. Information-disclosure bugs were fixed in Copilot, Microsoft 365 Copilot, Copilot Business Chat, and Azure Machine Learning, plus one Azure Portal spoofing flaw. Microsoft rated all 18 critical, though CVSS scores indicate high or medium for some; none were flagged as exploited and all fixes were implemented server-side, requiring no customer action. Separately, Microsoft patched a Windows privilege-escalation flaw tracked as CVE-2026-85921, deemed less likely to be exploited, after fixing a record 970 vulnerabilities in the latest Patch Tuesday.