Microsoft deployed server-side fixes for 18 vulnerabilities affecting Azure cloud services and Copilot-branded AI products, including Azure Billing, Microsoft Fabric, Container Registry, Logic Apps, AI Foundry, Azure Arc, Azure Database for PostgreSQL, Cosmos DB, Dataverse, and Microsoft 365 Copilot. A reported subset of 12 network-accessible flaws includes authentication and authorization bypasses, missing-authentication defects, path traversal, command injection, and other injection vulnerabilities; seven were assigned CVSS 10.0 scores. Additional issues include information-disclosure vulnerabilities in Copilot and Azure Machine Learning and a spoofing flaw in Azure Portal.
Microsoft rated the cloud and AI issues as critical, although individual published severity scores range from medium to critical. No active exploitation or CISA Known Exploited Vulnerabilities listings had been reported. The affected Azure and AI services were remediated by Microsoft, requiring no customer patching, but organizations should validate service status, review privileged identities, integrations, and container-registry activity for anomalies. Separately, Windows users must install updates for the elevation-of-privilege vulnerability CVE-2026-85921.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft also released a patch for the separate Windows elevation-of-privilege vulnerability CVE-2026-85921. Users must update Windows to remediate the flaw; Microsoft assessed exploitation as less likely.
Microsoft released server-side fixes for 18 vulnerabilities across Azure services and Copilot-branded AI products, including elevation-of-privilege, information-disclosure, and Azure Portal spoofing issues. Microsoft said none had been flagged as exploited and customers did not need to take action for the server-side fixes.
Microsoft disclosed 12 network-based privilege-escalation vulnerabilities affecting 10 managed Azure and Microsoft 365 services. The cluster included seven CVSS 10.0 flaws; no public exploitation or CISA KEV listings were reported.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.