Microsoft reportedly patched 18 vulnerabilities across Azure cloud services and Copilot-branded AI products. The fixes were reportedly implemented server-side, so customers did not need to take action for these service issues.
Reported vulnerability types and affected products
Privilege-escalation flaws accounted for most of the 18 reported vulnerabilities. The affected products included Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Billing, Azure HorizonDB, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Microsoft Dataverse and Microsoft 365 Copilot.
Reported information-disclosure flaws involved Copilot, Microsoft 365 Copilot, Microsoft 365 Copilot Business Chat and Azure Machine Learning. One reported spoofing vulnerability affected Azure Portal. None of the 18 vulnerabilities was reported as flagged as exploited.
What customers need to do
The 18 Azure and AI fixes were reportedly applied on the server side, so customers did not need to install an update for them. A separate Windows privilege-escalation vulnerability, CVE-2026-85921, requires users to install a Windows update.