THE CRUNCH
Microsoft has released updates to address 18 vulnerabilities across its Azure cloud portfolio and Copilot-branded AI products. Privilege escalation flaws were the most common issue, affecting services such as Azure ARC, Azure AI Foundry, and Microsoft 365 Copilot. The company rated all flaws as critical, though some carry high or medium severity scores.
The patch covers a range of products, including Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, and Microsoft Dataverse. Several information disclosure vulnerabilities were also addressed in Copilot and Azure Machine Learning. A single spoofing flaw was patched in the Azure Portal. Microsoft noted that fixes were implemented on the server side, meaning customers do not need to take action.
The vulnerabilities were discovered both internally and by external researchers. None have been flagged as exploited in the wild. Microsoft also patched a privilege escalation vulnerability affecting Windows this week, tracked as CVE-2026-85921, though it believes exploitation is less likely.


