Microsoft released patches for 18 vulnerabilities across Azure services and Copilot-branded AI products, with most issues involving elevation of privilege and several information disclosure flaws. The company said none of the bugs are known to be exploited, and all Azure and Copilot fixes were handled server-side, while Windows users must update for CVE-2026-85921. #AzureARC #AzureAIFoundry #AzureLogicApps #Microsoft365Copilot #CVE-2026-85921
Keypoints
- Microsoft patched 18 vulnerabilities across its Azure cloud portfolio and Copilot products.
- Most of the flaws were elevation of privilege issues affecting multiple Azure and Microsoft services.
- Information disclosure bugs were fixed in Copilot, Microsoft 365 Copilot, and Azure Machine Learning.
- All Azure and Copilot fixes were applied server-side, so customers do not need to take action.
- Microsoft also patched CVE-2026-85921 in Windows, which it says is less likely to be exploited.
Read More: https://www.securityweek.com/microsoft-patches-18-vulnerabilities-in-ai-cloud-products/