oxhak on Nostr: Microsoft released fixes for 18 vulnerabilities affecting its Azure cloud portfolio ...
Microsoft released fixes for 18 vulnerabilities affecting its Azure cloud portfolio and Copilot-branded AI products. Most were elevation-of-privilege flaws in Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Billing, Azure HorizonDB, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Microsoft Dataverse, and Microsoft 365 Copilot. Information-disclosure bugs affected Copilot, Microsoft 365 Copilot Business Chat, and Azure Machine Learning; Azure Portal received a spoofing fix.
Microsoft rated all of the vulnerabilities critical, although CVSS scores range from medium to high. None had been flagged as exploited, and all fixes were deployed server-side, so customers do not need to act. The disclosure matters because the affected services span cloud infrastructure, AI assistants, data platforms, and machine-learning systems, concentrating privilege and information-access risks across widely used enterprise products.
https://www.securityweek.com/microsoft-patches-18-vulnerabilities-in-ai-cloud-products/Published at
2026-09-18 11:05:57 UTCEvent JSON
{
"id": "6dba45a6109af38b9ba0636ae03b4b8e4b70dd1da01c0f8f123375c36d6b9ce3",
"pubkey": "81b26cb98224311ea520a9042bf9c7cc78d2725d0a99f9797afd9a8a35970aaa",
"created_at": 1789729557,
"kind": 1,
"tags": [],
"content": "Microsoft released fixes for 18 vulnerabilities affecting its Azure cloud portfolio and Copilot-branded AI products. Most were elevation-of-privilege flaws in Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Billing, Azure HorizonDB, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Microsoft Dataverse, and Microsoft 365 Copilot. Information-disclosure bugs affected Copilot, Microsoft 365 Copilot Business Chat, and Azure Machine Learning; Azure Portal received a spoofing fix.\n\nMicrosoft rated all of the vulnerabilities critical, although CVSS scores range from medium to high. None had been flagged as exploited, and all fixes were deployed server-side, so customers do not need to act. The disclosure matters because the affected services span cloud infrastructure, AI assistants, data platforms, and machine-learning systems, concentrating privilege and information-access risks across widely used enterprise products.\n\nhttps://www.securityweek.com/microsoft-patches-18-vulnerabilities-in-ai-cloud-products/",
"sig": "0cbdb664117e8cd0523f7ebf722df9adf09ec867401ed0f289a09c9c5c628cd0f5c4cc93c09c25b864d4d5d39717cfc65128702675c38b14eb49c4da9e101b66"
}