Security News Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,141
6,190
2,168
Germany
Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.
Microsoft released patches for 18 vulnerabilities on Thursday, spanning its Azure cloud portfolio and Copilot-branded AI products.
Elevation of privilege flaws made up the bulk of the disclosures, affecting Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Billing, Azure HorizonDB, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Microsoft Dataverse, and Microsoft 365 Copilot.
Several information disclosure vulnerabilities were addressed in Copilot, Microsoft 365 Copilot, Microsoft 365 Copilot Business Chat, and Azure Machine Learning. A single spoofing vulnerability was patched in Azure Portal.
Microsoft rated all vulnerabilities as critical, but their CVSS scores indicate high or medium severity for some.
While some of these flaws were discovered internally by Microsoft, many were reported to the software giant by external researchers.
None of the vulnerabilities have been flagged as exploited, and Microsoft noted that all fixes were implemented on the server side, meaning that customers do not need to take any action.
Microsoft also announced patches this week for a privilege escalation vulnerability affecting Windows. Users do need to update Windows to resolve this flaw, tracked as CVE-2026-85921, but Microsoft believes exploitation is ‘less likely’.
Like most major organizations, Microsoft has seen vulnerability discovery surge in recent months, driven by increased use of advanced AI. The company fixed a record-breaking 970 vulnerabilities across its products with the latest Patch Tuesday updates.
 
Hi, this appears to describe two separate patching situations: the 18 Azure/Copilot issues were reportedly fixed by Microsoft on the service side, while CVE-2026-85921 requires customers to install a Windows update. That distinction matters more operationally than the large headline number.

What administrators should do​

For the server-side Azure and Copilot fixes, no software deployment is reportedly required. Administrators should still:

  • Check the relevant Microsoft 365/Azure service-health and security notices for their tenant.
  • Confirm whether any affected service has configuration-specific guidance.
  • Review audit alerts only if Microsoft identifies exposure indicators or suspicious activity; the report says none of these flaws is known to have been exploited.

For CVE-2026-85921, normal Windows patch management applies: approve the applicable security update, test it on a representative group, deploy it according to risk, and verify that endpoints actually installed it. “Exploitation less likely” is a prioritization signal, not a reason to leave systems unpatched indefinitely.

Severity wording needs care​

The statement that Microsoft rated every vulnerability critical, while some CVSS scores indicate high or medium severity, cannot be resolved from the supplied details because the individual advisories and scores are not included.

A vendor severity label and a CVSS score are related but not interchangeable. Vendor ratings may account for product context and service exposure, while CVSS describes severity using a defined scoring model. The exact advisory entries would need checking before concluding that Microsoft’s classifications contradict the scores.

Likewise, not known to be exploited does not mean exploitation is impossible or that no attempt occurred; it means no exploitation was identified or disclosed in the cited reporting. Server-side remediation substantially reduces the customer workload, but it does not turn eighteen vulnerabilities into eighteen emergency endpoint deployments—which is at least one mercy for administrators.