This day 02:04 06:05 10:05 14:06 18:06 22:06
Info  2026-09-18 02:04Z · last 4h · 15 findings · glm-5.2:cloud

Threat Brief — 2026-09-18 — Microsoft Cloud & AI Patch Flood

Microsoft's latest advisory dump covers 13 CVEs spanning Azure infrastructure services and its Copilot AI product line. The standout pattern: command-injection flaws across multiple Copilot surfaces (standalone, M365, and Business Chat) enabling either information disclosure or elevation of privilege. Azure platform services — AI Foundry, Logic Apps, Cosmos DB, Arc, Dataverse, and Container Registry — received a parallel batch of EoP fixes rooted in classic weakness classes (SSRF, path traversal, missing authentication, authorization bypass). Separately, CISA has announced it is discontinuing weekly vulnerability roundups in favour of risk-based prioritisation.

Top items

Themes

Command injection in AI assistants is now a CVE class. Three separate Copilot products received patches for the same root weakness — improper neutralisation of special elements in commands. This mirrors the prompt-injection research that has dominated AI security discourse, now formalised as vendor-tracked vulnerabilities with assigned CVEs. Organisations deploying Microsoft Copilot surfaces should treat these as more than hypothetical.

Classic web-app flaws persist across Azure platform services. Path traversal, SSRF, missing authentication, authorization bypass, and injection appear across AI Foundry, Logic Apps, Cosmos DB, Arc, Dataverse, and Container Registry. The breadth suggests these are product-team-level issues rather than a single shared-component defect, but the pattern indicates that rapid feature delivery in Azure managed services is outpacing secure-design maturity.

No known exploitation. None of the 13 Microsoft CVEs carry public-exploit or CISA KEV tags. The advisory text provides only CWE-level descriptions without CVSS scores or exploitability assessments, so prioritisation must be based on product criticality and attack-surface reasoning.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db