Microsoft Fixes 18 Cloud and AI Vulnerabilities with Server-Side Patches
Microsoft has released patches for 18 vulnerabilities in its AI and cloud products. The majority of these flaws involved elevation of privilege, affecting services such as Azure ARC and Copilot.
The patches addressed information disclosure vulnerabilities in Copilot and Microsoft 365 Copilot Business Chat. Additionally, a spoofing vulnerability in Azure Portal received a patch.
All fixes for the AI and cloud vulnerabilities were implemented on the server side, meaning customers do not need to take any direct action. However, users are required to update their Windows systems to resolve a separate privilege escalation vulnerability tracked as CVE-2026-85921.