Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing Flaws Across Azure and Copilot AI Products, Plus a Windows Secure Kernel EoP (CVE-2026-85921)

Microsoft September 2026 Cloud Disclosure (TL-2026-2563), also tracked as Microsoft September 2026 Azure/Copilot Cloud CVE Batch, is a critical-severity software vulnerability scored CVSS 10, first published 2026-09-18. It has no confirmed attribution, affects Microsoft Windows 11 26H1, references 19 CVEs (CVE-2026-85921, CVE-2026-69399, CVE-2026-70009), maps to 10 MITRE ATT&CK techniques (T1059.007, T1078.004, T1119), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-2563

Threat ID
TL-2026-2563
Also known as
Microsoft September 2026 Azure/Copilot Cloud CVE Batch
Severity
CRITICAL
CVSS
10
Status
PATCHED
Category
VULNERABILITY
First published
2026-09-18
Last reviewed
2026-09-18
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, cloudcomputing, government administration, finance, health, enterpriseit, professionalservices
Target regions
Global
Detection rules
9
Indicators of compromise
20

On September 17-18, 2026, Microsoft disclosed a batch of 18 vulnerabilities spanning Azure infrastructure services (Arc, AI Foundry, Logic Apps, Billing, HorizonDB/PostgreSQL, Cosmos DB, Container Registry), Microsoft Fabric, Microsoft Dataverse, and Copilot AI products (Microsoft Copilot, Microsoft 365 Copilot, Copilot Business Chat, Azure Machine Learning, Azure Portal) - mostly elevation-of-privilege, plus information disclosure and one spoofing flaw. A separately flagged Windows Secure Kernel Mode double-free elevation-of-privilege bug (CVE-2026-85921) was published in the same window and required a client-side update. None of the 19 vulnerabilities has been exploited in the wild or has a public proof-of-concept; all 18 cloud-service fixes were applied server-side with no customer action.

How Microsoft September 2026 Cloud Disclosure works

Microsoft's Security Response Center (MSRC) published a dense cluster of CVEs on September 17, 2026, one day ahead of SecurityWeek's roundup coverage, covering the Azure and Microsoft 365 Copilot AI surface. The majority of the disclosures (at least 15 of the 18) are elevation-of-privilege vulnerabilities: two in Azure Arc (CVE-2026-69399, CVE-2026-70009, both improper-authorization issues), two in Azure AI Foundry (CVE-2026-85917, a server-side request forgery, and CVE-2026-85889, a missing-authentication-for-critical-function flaw - both exploitable by an unauthorized network attacker against the AI Foundry control plane), one in Azure Logic Apps (CVE-2026-83944, improper access control rated CVSS 10.0), one in Azure Billing (CVE-2026-62874, insufficient verification of data authenticity), one in Azure HorizonDB / Azure Database for PostgreSQL (CVE-2026-85878, improper authorization, CVSS ~9.9), one in Azure Cosmos DB (CVE-2026-87701), one in Azure Container Registry (CVE-2026-69865, an authorization bypass through a user-controlled key, CVSS 10.0, remotely exploitable pre-auth), two in Microsoft Fabric (CVE-2026-69843, authentication bypass by spoofing, and CVE-2026-70178, missing authorization), one in Microsoft Dataverse (CVE-2026-77903), and two open-redirect elevation-of-privilege bugs in Microsoft 365 Copilot (CVE-2026-41106) and its Business Chat feature (CVE-2026-47645) that require a victim to follow a crafted link. Information-disclosure flaws were fixed in Microsoft Copilot (CVE-2026-55946, a command-injection issue), Microsoft 365 Copilot (CVE-2026-85887, incorrect permission assignment for a critical resource - both capable of leaking a user's connected emails, Teams chats, Word documents, and SharePoint content given Copilot's deep tenant integration), and Azure Machine Learning (CVE-2026-68791, incorrect authorization / CWE-863, letting an unauthenticated caller send crafted requests manipulating workspace IDs, project names, or model identifiers to pull back sensitive workspace data). One spoofing vulnerability was fixed in Azure Portal (CVE-2026-83946, a stored cross-site-scripting flaw, CWE-79, CVSS 8.2, that could let an attacker manipulate the portal UI or steal authenticated session tokens). Separately, and not counted in the '18,' Microsoft published CVE-2026-85921, a Critical Windows Secure Kernel Mode elevation-of-privilege vulnerability caused by a double free (CWE-415) that lets a locally authorized attacker escalate to Virtual Trust Level 1 (VTL1) - the hardware-backed security boundary Windows uses to isolate credential material and kernel integrity checks from a compromised normal-mode OS. Unlike the cloud-service fixes, CVE-2026-85921 required customers to install a client-side update (Microsoft shipped it via the out-of-band KB5129194 cumulative update for Windows 11 26H1, OS Build 28000.2956, released September 14, 2026). Microsoft internally rates all 18 cloud-service CVEs as 'Critical' by its own severity taxonomy even though third-party CVSS recalculations put several in the high-to-medium band; none of the 19 vulnerabilities in this batch has been observed exploited in the wild, has known public exploit code, or appears on the CISA Known Exploited Vulnerabilities catalog, and Microsoft assesses exploitation of CVE-2026-85921 specifically as 'less likely.' The disclosure lands the same week MSRC's blog announced it is expanding machine-readable Vulnerability Exploitability eXchange (VEX) statements to all Microsoft-assigned CVEs, part of its 'Toward Greater Transparency' cloud-service-CVE program, under which server-side-only fixes for multi-tenant cloud products are now routinely assigned and published CVEs even though customers take no remediation action themselves.

MITRE ATT&CK techniques used in TL-2026-2563

Execution

T1059.007 JavaScript; T1204.001 Malicious Link

Privilege Escalation

T1078.004 Cloud Accounts

Collection

T1119 Automated Collection; T1213 Data from Information Repositories

Initial Access

T1190 Exploit Public-Facing Application

Credential Access

T1539 Steal Web Session Cookie; T1552 Unsecured Credentials

lateral-movement

T1550 Use Alternate Authentication Material

Discovery

T1580 Cloud Infrastructure Discovery

Affected products and versions in Microsoft September 2026 Cloud Disclosure

  • Microsoft — Windows 11 26H1
    Vulnerable versions: OS Build 28000.x prior to 28000.2956
    Fixed in: OS Build 28000.2956 via KB5129194
  • Microsoft — Azure Arc
    Vulnerable versions: cloud service - all tenants prior to Sept 17, 2026 server-side fix
    Fixed in: server-side patched, no customer action
  • Microsoft — Azure AI Foundry
    Vulnerable versions: cloud service - all tenants prior to Sept 17, 2026 server-side fix
    Fixed in: server-side patched, no customer action
  • Microsoft — Azure Logic Apps
    Vulnerable versions: cloud service - all tenants prior to Sept 17, 2026 server-side fix
    Fixed in: server-side patched, no customer action
  • Microsoft — Azure Billing
    Vulnerable versions: cloud service - all tenants prior to Sept 17, 2026 server-side fix
    Fixed in: server-side patched, no customer action
  • Microsoft — Azure HorizonDB / Azure Database for PostgreSQL
    Vulnerable versions: cloud service - all tenants prior to Sept 17, 2026 server-side fix
    Fixed in: server-side patched, no customer action
  • Microsoft — Azure Cosmos DB
    Vulnerable versions: cloud service - all tenants prior to Sept 17, 2026 server-side fix
    Fixed in: server-side patched, no customer action
  • Microsoft — Azure Container Registry
    Vulnerable versions: cloud service - all tenants prior to Sept 17, 2026 server-side fix
    Fixed in: server-side patched, no customer action
  • Microsoft — Microsoft Fabric
    Vulnerable versions: cloud service - all tenants prior to Sept 17, 2026 server-side fix
    Fixed in: server-side patched, no customer action
  • Microsoft — Microsoft Dataverse
    Vulnerable versions: cloud service - all tenants prior to Sept 17, 2026 server-side fix
    Fixed in: server-side patched, no customer action

Remediation for Microsoft September 2026 Cloud Disclosure

Patches

  • KB5129194 (Windows 11 26H1, OS Build 28000.2956) - out-of-band, remediates CVE-2026-85921
  • Server-side Microsoft fixes (no customer package/version to apply) for CVE-2026-69399, CVE-2026-70009 (Azure Arc), CVE-2026-85917, CVE-2026-85889 (Azure AI Foundry), CVE-2026-83944 (Azure Logic Apps), CVE-2026-62874 (Azure Billing), CVE-2026-85878 (Azure HorizonDB/Azure Database for PostgreSQL), CVE-2026-87701 (Azure Cosmos DB), CVE-2026-69865 (Azure Container Registry), CVE-2026-69843, CVE-2026-70178 (Microsoft Fabric), CVE-2026-77903 (Microsoft Dataverse), CVE-2026-41106 (Microsoft 365 Copilot), CVE-2026-47645 (Copilot Business Chat), CVE-2026-55946 (Microsoft Copilot), CVE-2026-85887 (Microsoft 365 Copilot), CVE-2026-68791 (Azure Machine Learning), CVE-2026-83946 (Azure Portal)

Immediate actions

  • Confirm tenant-level exposure is closed: the 18 Azure/Copilot fixes were applied server-side by Microsoft and require no customer action, but verify via the Azure Service Health / Microsoft 365 Message Center that the relevant service updates have rolled out to your tenant's region.
  • Install the out-of-band Windows update KB5129194 (OS Build 28000.2956) on all Windows 11 26H1 endpoints to remediate CVE-2026-85921.
  • Audit Azure AI Foundry, Azure Container Registry, and Azure Cosmos DB access logs for anomalous unauthenticated or cross-tenant requests predating the September 17, 2026 patch, since several of the flaws (SSRF, missing authentication, user-controlled-key authorization bypass) were remotely exploitable pre-auth.
  • Review Microsoft 365 Copilot and Copilot Business Chat sign-in/redirect logs for unexpected external redirect targets that could indicate open-redirect abuse tied to CVE-2026-41106 / CVE-2026-47645.

Workarounds

  • None published or required for the 18 cloud-service CVEs; Microsoft states the fixes are fully deployed server-side.
  • For CVE-2026-85921, defense-in-depth prior to patching includes restricting local logon rights on affected Windows 11 26H1 hosts, since exploitation requires local, authorized access.

Longer-term hardening

  • Subscribe to Microsoft's expanded VEX (Vulnerability Exploitability eXchange) machine-readable feed to automate cloud-service-CVE exposure tracking rather than relying on manual Patch Tuesday review.
  • Extend vulnerability-management scope to explicitly cover PaaS/SaaS control-plane services (AI Foundry, Fabric, Dataverse, Cosmos DB, Container Registry) that receive CVEs but never appear in traditional endpoint patch compliance tooling.
  • Implement DLP and audit logging specifically for Copilot data-access paths (email, Teams, SharePoint, Word) given the recurring pattern of Copilot information-disclosure CVEs.
  • Harden Azure AI Foundry outbound network policies to reduce SSRF blast radius from control-plane services with broad internal network reach.

CVEs associated with Microsoft September 2026 Cloud Disclosure

Weaknesses (CWE) in Microsoft September 2026 Cloud Disclosure

CWE-415, CWE-269, CWE-918, CWE-306, CWE-862, CWE-345, CWE-863, CWE-639, CWE-290, CWE-601

Timeline of Microsoft September 2026 Cloud Disclosure

  • Microsoft ships KB5129194, an out-of-band Windows 11 26H1 (OS Build 28000.2956) cumulative update, ahead of the main September servicing cycle.
  • MSRC publishes CVE-2026-85921, a Critical Windows Secure Kernel Mode double-free elevation-of-privilege vulnerability (CWE-415) allowing a locally authorized attacker to obtain Virtual Trust Level 1 (VTL1) privileges; Microsoft rates exploitation 'less likely' and confirms no public disclosure or in-the-wild exploitation.
  • MSRC publishes a blog post expanding machine-readable Vulnerability Exploitability eXchange (VEX) statements to all Microsoft-assigned CVEs, the same 'Toward Greater Transparency' program under which the server-side-only Azure/Copilot CVEs in this batch are disclosed.
  • Microsoft discloses an Azure Machine Learning information-disclosure flaw (CVE-2026-68791, incorrect authorization, CWE-863) and an Azure Portal spoofing vulnerability (CVE-2026-83946, stored cross-site scripting, CWE-79, CVSS 8.2).
  • Microsoft discloses information-disclosure flaws in Microsoft Copilot (CVE-2026-55946, command injection) and Microsoft 365 Copilot (CVE-2026-85887, incorrect permission assignment for a critical resource), both capable of leaking tenant email, Teams, and SharePoint content given Copilot's deep data integration.
  • Microsoft discloses open-redirect elevation-of-privilege vulnerabilities in Microsoft 365 Copilot (CVE-2026-41106) and its Business Chat feature (CVE-2026-47645), both fully mitigated server-side with no customer action.
  • Microsoft discloses elevation-of-privilege issues in Azure Logic Apps (CVE-2026-83944, improper access control, CVSS 10.0), Azure Billing (CVE-2026-62874), Microsoft Fabric (CVE-2026-69843 authentication bypass by spoofing; CVE-2026-70178 missing authorization), and Microsoft Dataverse (CVE-2026-77903).
  • Microsoft discloses elevation-of-privilege flaws in Azure Cosmos DB (CVE-2026-87701), Azure HorizonDB/Azure Database for PostgreSQL (CVE-2026-85878), Azure Container Registry (CVE-2026-69865, authorization bypass via a user-controlled key), and Azure Arc (CVE-2026-69399, CVE-2026-70009).
  • Microsoft discloses two Azure AI Foundry elevation-of-privilege vulnerabilities: CVE-2026-85917 (server-side request forgery) and CVE-2026-85889 (missing authentication for a critical function), both exploitable by an unauthorized network attacker against the AI Foundry control plane.
  • SecurityWeek publishes 'Microsoft Patches 18 Vulnerabilities in AI, Cloud Products,' summarizing the batch of 18 Azure/Copilot fixes plus the separately flagged Windows kernel flaw, and confirms all server-side fixes required no customer action and none of the 18 were flagged as exploited in the wild.

Sources cited for Microsoft September 2026 Cloud Disclosure

More in vulnerability

Detection coverage for TL-2026-2563

As of 2026-09-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2563 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats