Skip to content

Security1 publisher2 min readPublished

Microsoft cleared 18 Azure and Copilot vulnerabilities server-side in one out-of-band batch

The bugs sit in 14 named Azure and Copilot services and Microsoft rated all 18 critical, but the fixes were already running in production when the disclosure went out, so tenants cannot install or verify anything themselves.

The Watch · Security desk

Illustration accompanying Microsoft cleared 18 Azure and Copilot vulnerabilities server-side in one out-of-band batch

What happened

  • Microsoft released fixes for 18 vulnerabilities on Thursday, all of them in its Azure cloud portfolio or its Copilot-branded AI products.
  • Elevation of privilege accounted for most of them, hitting Azure ARC, AI Foundry, Logic Apps, Billing, HorizonDB, Cosmos DB, Container Registry, Microsoft Fabric, Dataverse and Microsoft 365 Copilot.
  • Information disclosure bugs were fixed in Copilot, Microsoft 365 Copilot, Microsoft 365 Copilot Business Chat and Azure Machine Learning, plus one spoofing flaw in Azure Portal.
  • Microsoft says all the fixes were implemented on the server side and that customers do not need to take any action, and none of the 18 has been flagged as exploited.
  • A separate Windows privilege escalation flaw, CVE-2026-85921, does require customers to update, and Microsoft believes exploitation of it is less likely.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • contradiction Microsoft labelled all 18 critical while the CVSS scores land some at high or medium, so the vendor rating and the score disagree for anyone building a triage order from either one.
  • constraint Remediation of the Azure and Copilot surface happens server-side, so an operator cannot independently confirm the fix or date it from their own systems.
  • exposure The 18 came without identifiers, so they cannot be entered into a tenant's vulnerability register, and an auditor asking what was wrong and when it closed gets Microsoft's summary as the only record.
  • decision The only scheduling call this week is the Windows bug, and Microsoft's own 'less likely' exploitation rating pushes it down a queue already holding this month's Patch Tuesday load.

Elevation of privilege in a managed service means the attack path ran through Microsoft's control planes, not through anything a tenant installs [2]. The remedy is a deployment on Microsoft's side. Microsoft says every one of the 18 was fixed server-side and that customers do not need to take any action [8].

That leaves a records problem. There is no KB number to file and no build number to compare. An operator asked to show when Azure Cosmos DB or Microsoft Dataverse stopped being exploitable has Microsoft's statement and the date it was published [2][8].

Add up the products named in the disclosure: ten in the elevation-of-privilege list, four in the information disclosure list with Microsoft 365 Copilot appearing in both, and Azure Portal for the single spoofing bug. Fourteen named services carry the 18 flaws [12].

Microsoft rated all of them critical, while the CVSS scores put some at high or medium [5]. For software you deploy, that gap decides what goes first into the window. For a service that has already been fixed, the field that still does anything for a defender is exploitation status, and none of the 18 has been flagged as exploited [7]. Some were found by Microsoft internally, many by external researchers [6].

SecurityWeek identified exactly one of this week's flaws by number, and it is the one that behaves like a normal patch: CVE-2026-85921, an elevation of privilege bug in Windows that users do have to install [9][14]. Microsoft believes exploitation of it is "less likely" [9]. The cloud and AI half is closed and unverifiable from the customer side; the Windows half is open and sits in the same maintenance queue as everything else this month.

Microsoft fixed a record 970 vulnerabilities in the latest Patch Tuesday [10], and the company attributes the recent surge in discovery in part to increased use of advanced AI [11]. The 18 here are under two percent of that count [15].

What to watch

  • Whether Microsoft publishes CVE identifiers for the 18 cloud and AI flaws so tenants can reference them in their own vulnerability registers.
  • Any report of exploitation attempts before the server-side deployments completed. Microsoft's timeline would be the only evidence customers hold.
  • Whether the next out-of-band batch again lands entirely in services that require no customer action.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories