Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Microsoft has rolled out patches for 18 critical vulnerabilities affecting its Azure cloud portfolio and Copilot-branded AI products. These flaws, which include elevation of privilege and information disclosure issues, were discovered by both internal Microsoft researchers and external security experts.

The majority of the vulnerabilities, 14 in total, are classified as elevation of privilege (EoP) flaws. This type of vulnerability allows attackers to gain unauthorized access to sensitive systems or data, potentially leading to a wide range of malicious activities. The affected products include Azure ARC, Azure AI Foundry, Azure Logic Apps, and several other cloud-based services.

Microsoft has also addressed several information disclosure vulnerabilities in its Copilot products, which are designed to provide AI-powered assistance to users. Information disclosure issues can expose sensitive data or allow attackers to gather valuable intelligence about an organization’s systems and security controls.

A single spoofing vulnerability was patched in Azure Portal, a web interface used by administrators to manage various Azure services. While Microsoft has not reported any instances of exploitation for these vulnerabilities, the company has rated all 18 as critical, indicating that they pose a significant risk to affected organizations.

It’s worth noting that some of the vulnerabilities have been assigned a lower severity rating based on their CVSS scores. This is because while the flaws are critical in nature, they may be more difficult for attackers to exploit or require specific circumstances to trigger an attack.

The patches were released as part of Microsoft’s regular Patch Tuesday updates, which aim to fix security issues across its products and services. The company has seen a significant increase in vulnerability discovery in recent months, driven by the growing use of advanced AI technologies. In fact, Microsoft fixed a record-breaking 970 vulnerabilities across its products with its latest Patch Tuesday updates.

Fortunately for customers, all fixes were implemented on the server side, meaning that users do not need to take any action to protect themselves. However, it’s essential for organizations to keep their systems and software up-to-date to ensure they have the latest security patches and protections in place.

This incident serves as a reminder of the importance of staying vigilant and proactive when it comes to cybersecurity. With the increasing reliance on cloud-based services and AI technologies, it’s more crucial than ever for organizations to prioritize security and regularly review their systems and software for potential vulnerabilities.


Source: SecurityWeek — 2026-09-18