Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Microsoft patched 18 elevation-of-privilege and information-disclosure vulnerabilities across Azure and Copilot products; all fixed server-side with no exploitation observed.
Microsoft on Thursday released patches for 18 vulnerabilities spanning its Azure cloud portfolio and Copilot-branded AI products, with elevation-of-privilege flaws affecting Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Dataverse, and Microsoft 365 Copilot, among others. Information-disclosure bugs were fixed in Copilot, Microsoft 365 Copilot, Copilot Business Chat, and Azure Machine Learning, plus one Azure Portal spoofing flaw. Microsoft rated all 18 critical, though CVSS scores indicate high or medium for some; none were flagged as exploited and all fixes were implemented server-side, requiring no customer action. Separately, Microsoft patched a Windows privilege-escalation flaw tracked as CVE-2026-85921, deemed less likely to be exploited, after fixing a record 970 vulnerabilities in the latest Patch Tuesday.
- 18 flaws patched across Azure and Copilot products, mostly elevation of privilege
- Info-disclosure bugs fixed in Copilot, Business Chat, and Azure Machine Learning
- No exploitation observed; all fixes server-side, no customer action needed
- Windows privilege escalation CVE-2026-85921 patched; exploitation deemed less likely
- Microsoft fixed a record 970 vulnerabilities in latest Patch Tuesday
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-85921 | Double Free in Windows Secure Kernel Mode Enables Local Privilege Escalation CVE-2026-85921 is a double free flaw (CWE-415) in Windows Secure Kernel Mode, the hypervisor-based component that underpins Virtualization-Based Security (VBS) on Windows clients and servers. It is triggered locally by an already-authorized attacker who holds high privileges on the machine (per the CVSS vector, privileges required: high), and successful exploitation lets them elevate privileges across a security boundary — escaping the isolation that Secure Kernel is meant to enforce — with high impact on confidentiality, integrity, and availability. In practice, an attacker with administrative code execution on a VBS-enabled host could leverage the bug to break out of or subvert the secure-kernel boundary and gain deeper, SYSTEM/hypervisor-adjacent control of the system. Any Windows deployment running Secure Kernel Mode (i.e., with VBS/HVCI or Hyper-V-based isolation enabled) is in scope. As of this writing there is no known public proof of concept, and the flaw is not listed in CISA's Known Exploited Vulnerabilities catalog. Do: Apply the Microsoft security update covering this CVE to all VBS/HVCI-enabled Windows clients and servers as soon as it is available, prioritizing servers and privileged workstations where admins and service accounts already hold elevated rights. Because exploitation requires an attacker who already has high local privileges, enforce least-privilege account policies, restrict local administrator membership, and monitor for anomalous activity from privileged processes around virtualization components. After patching, verify VBS/HVCI remains enabled and healthy (e.g., via msinfo32 or Get-CimInstance -ClassName Win32_DeviceGuard) to confirm the secure-kernel protections are intact. | 8.2 | — |
| massPotentially hundreds of millions of devices (order of 10^8) |
Full article269 words · extracted from securityweek.com · click to collapse
Microsoft released patches for 18 vulnerabilities on Thursday, spanning its Azure cloud portfolio and Copilot-branded AI products.
Elevation of privilege flaws made up the bulk of the disclosures, affecting Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Billing, Azure HorizonDB, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Microsoft Dataverse, and Microsoft 365 Copilot.
Several information disclosure vulnerabilities were addressed in Copilot, Microsoft 365 Copilot, Microsoft 365 Copilot Business Chat, and Azure Machine Learning. A single spoofing vulnerability was patched in Azure Portal.
Microsoft rated all vulnerabilities as critical, but their CVSS scores indicate high or medium severity for some.
While some of these flaws were discovered internally by Microsoft, many were reported to the software giant by external researchers.
None of the vulnerabilities have been flagged as exploited, and Microsoft noted that all fixes were implemented on the server side, meaning that customers do not need to take any action.
Advertisement. Scroll to continue reading.
Microsoft also announced patches this week for a privilege escalation vulnerability affecting Windows. Users do need to update Windows to resolve this flaw, tracked as CVE-2026-85921, but Microsoft believes exploitation is ‘less likely’.
Like most major organizations, Microsoft has seen vulnerability discovery surge in recent months, driven by increased use of advanced AI. The company fixed a record-breaking 970 vulnerabilities across its products with the latest Patch Tuesday updates.
Related: Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?
Related: Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints
Related: New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/microsoft-patches-18-vulnerabilities-in-ai-cloud-products/