Microsoft: 24 Azure & AI Vulnerabilities Disclosed, Including Critical Privilege Escalation Flaws
Microsoft disclosed 24 vulnerabilities across Azure and AI products from Sept 14-18, 2026, including critical flaws allowing privilege escalation and remote code execution.

Key findings
- Microsoft disclosed 24 vulnerabilities across Azure and AI products between Sept 14-18, 2026.
- Multiple critical flaws (CVSS 10.0) in Azure AI Foundry, Fabric, and Logic Apps allow privilege escalation.
- Vulnerabilities affect Azure AI Foundry, M365 Copilot, Azure Logic Apps, Azure Billing, Microsoft Fabric, and Azure Arc.
- Privilege escalation is the primary impact, with some CVEs allowing remote code execution.
- Microsoft Edge (Chromium-based) has multiple high-severity vulnerabilities including use-after-free and buffer overflows.
On September 17-18, 2026, Microsoft disclosed a significant batch of 24 vulnerabilities affecting various products across its Azure cloud portfolio and AI offerings. The disclosures, spanning from September 14th to the 18th, include several critical flaws with CVSS scores reaching the maximum of 10.0, primarily impacting Azure AI Foundry, Azure Logic Apps, Azure Billing, and Microsoft Fabric. These vulnerabilities predominantly allow for privilege escalation and information disclosure over a network, posing a substantial risk to organizations utilizing these services.
A cluster of critical vulnerabilities, all rated CVSS 10.0, were disclosed on September 17th. CVE-2026-69843 in Microsoft Fabric allows for authentication bypass by spoofing, enabling unauthorized privilege escalation. Similarly, CVE-2026-62874 in Azure Billing involves insufficient verification of data authenticity, leading to privilege escalation. Azure AI Foundry is particularly affected, with CVE-2026-85889, a critical flaw involving missing authentication for a critical function, allowing unauthenticated attackers to escalate privileges over a network. This specific vulnerability was highlighted by Cyber Security News and The Hacker News, with the latter crediting security researcher Rémy Marot. Another critical flaw in Azure AI Foundry, CVE-2026-85878, involves improper authorization, also leading to privilege escalation.
Further critical vulnerabilities disclosed on September 17th include CVE-2026-85885, a command injection flaw in M365 Copilot, and CVE-2026-83944, an improper access control vulnerability in Azure Logic Apps, both allowing privilege escalation. Path traversal vulnerabilities were also present, with CVE-2026-70200 in Azure Logic Apps and CVE-2026-70009 in Azure Arc enabling privilege escalation. CVE-2026-69865 in Microsoft Container Registry, an authorization bypass through user-controlled key, and CVE-2026-69399, an elevation of privilege vulnerability in Azure Arc, also carry critical severity. CVE-2026-87701 in Azure Cosmos DB, an injection flaw, and CVE-2026-77903 in Microsoft Dataverse, an authentication bypass by spoofing, further contribute to the critical risk profile.
High-severity vulnerabilities were also prevalent. CVE-2026-88097 and CVE-2026-85893, both use-after-free vulnerabilities in Microsoft Edge (Chromium-based), allow for local privilege escalation. CVE-2026-69486, a heap-based buffer overflow in Microsoft Edge, permits remote code execution. CVE-2026-85921, a double free vulnerability in Windows Secure Kernel Mode, allows for local privilege escalation. Additionally, CVE-2026-85892, a race condition in Microsoft Edge, also enables local privilege escalation. Information disclosure vulnerabilities were found in M365 Copilot (CVE-2026-85887), Azure Machine Learning (CVE-2026-68791), and Microsoft Copilot (CVE-2026-55946), with the latter being a command injection flaw. CVE-2026-85917, a server-side request forgery (SSRF) in Azure AI Foundry, also allows for privilege escalation.
The batch also includes a spoofing vulnerability, CVE-2026-83944, in the Azure Portal, allowing unauthorized attackers to perform spoofing over a network. SecurityWeek reported that Microsoft patched a total of 18 vulnerabilities in this disclosure cycle, affecting a wide range of its AI and cloud products, with elevation of privilege flaws being the most common. While Microsoft rated all vulnerabilities as critical, their CVSS scores indicate varying levels of severity.
Users are advised to ensure their Microsoft products, particularly those within the Azure ecosystem and M365 Copilot, are updated to the latest versions to mitigate these risks. The widespread nature of these vulnerabilities underscores the importance of continuous security monitoring and prompt patching for cloud environments.
The disclosures occurred between September 14 and September 18, 2026. The most severe flaws, including multiple CVSS 10.0 rated vulnerabilities, were disclosed on September 17th and 18th. The affected products span Microsoft's cloud infrastructure and AI services, including Azure AI Foundry, Azure Logic Apps, Azure Billing, Microsoft Fabric, Microsoft Edge, and M365 Copilot. The primary impact of these vulnerabilities is privilege escalation, with some allowing for remote code execution and information disclosure. CVE-2026-85889, a critical flaw in Azure AI Foundry, was specifically highlighted for its potential to allow unauthenticated privilege escalation. Organizations should prioritize patching these vulnerabilities to protect their cloud environments and sensitive data.