Threat Brief — 2026-09-18 — Microsoft Cloud & AI Patch Flood
Microsoft's latest advisory dump covers 13 CVEs spanning Azure infrastructure services and its Copilot AI product line. The standout pattern: command-injection flaws across multiple Copilot surfaces (standalone, M365, and Business Chat) enabling either information disclosure or elevation of privilege. Azure platform services — AI Foundry, Logic Apps, Cosmos DB, Arc, Dataverse, and Container Registry — received a parallel batch of EoP fixes rooted in classic weakness classes (SSRF, path traversal, missing authentication, authorization bypass). Separately, CISA has announced it is discontinuing weekly vulnerability roundups in favour of risk-based prioritisation.
Top items
- Azure AI Foundry — two EoP CVEs (SSRF + missing authentication). CVE-2026-85917 allows an unauthenticated network attacker to exploit SSRF for privilege escalation; CVE-2026-85889 exploits a missing-authentication gap for the same outcome. Both affect a service designed to host AI workloads, making lateral movement from an SSRF foothold the primary concern. (src: MSRC) (src: MSRC)
- Microsoft Copilot command-injection cluster — three CVEs across Copilot surfaces. CVE-2026-55946 (Microsoft Copilot, unauthenticated info disclosure), CVE-2026-85885 (M365 Copilot, authenticated EoP), and CVE-2026-78501 (M365 Copilot Business Chat, unauthenticated info disclosure) all stem from improper neutralisation of special elements in commands. The spread across three distinct Copilot products suggests a systemic prompt/command-injection class problem in Microsoft's AI assistant architecture. (src: MSRC) (src: MSRC) (src: MSRC)
- Azure Logic Apps — two EoP CVEs (path traversal + improper access control). CVE-2026-70200 enables path-traversal-based privilege escalation; CVE-2026-83944 exploits an access-control gap. Both are unauthenticated and network-reachable. Logic Apps frequently handle workflow orchestration with broad integration permissions, so EoP here can translate into access to connected SaaS systems. (src: MSRC) (src: MSRC)
- Azure Cosmos DB — injection-based EoP (CVE-2026-87701). An authorised attacker can exploit injection of special elements in output consumed by a downstream component to escalate privileges. The authorised-attacker precondition narrows the attack surface but is still significant in multi-tenant or shared-access scenarios. (src: MSRC)
- Microsoft Dataverse — authentication bypass by spoofing (CVE-2026-77903). An unauthenticated network attacker can spoof authentication to escalate privileges. Dataverse underpins Dynamics 365 and Power Platform, so a spoofing-based EoP could grant access to business-critical data flows. (src: MSRC)
- Microsoft Container Registry — authorization bypass via user-controlled key (CVE-2026-69865). An unauthenticated attacker can exploit a user-controlled-key bypass to escalate privileges. Container registries are high-value targets for supply-chain compromise, making this worth prioritising despite limited detail in the advisory. (src: MSRC)
- Azure Arc — two EoP CVEs (path traversal + unspecified). CVE-2026-70009 enables path-traversal-based EoP; CVE-2026-69399 has no technical detail beyond "information published." Azure Arc manages hybrid and multi-cloud resources, so compromise could bridge on-premises and cloud trust boundaries. (src: MSRC) (src: MSRC)
- Azure Machine Learning — information disclosure via incorrect authorization (CVE-2026-68791). An unauthenticated network attacker can access information they should not. ML workspaces often contain training data, model artefacts, and credentials, making disclosure potentially high-impact. (src: MSRC)
- CISA discontinues weekly vulnerability roundups in favour of risk-based focus. The agency will no longer publish its weekly summary of CVEs, instead concentrating on vulnerabilities that pose actual exploitation risk. This aligns with CISA's broader push for risk-driven patch prioritisation and may reduce noise but also removes a passive discovery channel for some teams. (src: Dark Reading)
- Unit 42 publishes guidance on cross-environment pivot attacks for SOC teams. The article describes how attackers chain compromises across cloud, on-premises, and SaaS environments and advocates full attack-path investigation rather than siloed alert triage. This is analytical/educational content rather than a new threat disclosure. (src: Unit 42)
Themes
Command injection in AI assistants is now a CVE class. Three separate Copilot products received patches for the same root weakness — improper neutralisation of special elements in commands. This mirrors the prompt-injection research that has dominated AI security discourse, now formalised as vendor-tracked vulnerabilities with assigned CVEs. Organisations deploying Microsoft Copilot surfaces should treat these as more than hypothetical.
Classic web-app flaws persist across Azure platform services. Path traversal, SSRF, missing authentication, authorization bypass, and injection appear across AI Foundry, Logic Apps, Cosmos DB, Arc, Dataverse, and Container Registry. The breadth suggests these are product-team-level issues rather than a single shared-component defect, but the pattern indicates that rapid feature delivery in Azure managed services is outpacing secure-design maturity.
No known exploitation. None of the 13 Microsoft CVEs carry public-exploit or CISA KEV tags. The advisory text provides only CWE-level descriptions without CVSS scores or exploitability assessments, so prioritisation must be based on product criticality and attack-surface reasoning.
