The gist: Microsoft security vulnerabilities in Azure, Copilot, Exchange and Surface enable privilege escalation and code execution.
The Federal Office for Information Security (BSI) warns of multiple security vulnerabilities in Microsoft products. Affected are Azure, Microsoft 365 Copilot, Exchange and Surface apps — attackers can use these to execute code, escalate privileges or disclose data.
According to the BSI security advisory WID-SEC-2026-2502, several critical components of the Microsoft ecosystem are affected: the cloud platform Azure, the AI assistant Copilot within Microsoft 365, the email server Exchange, and apps for Surface devices.
The vulnerabilities enable attackers a range of serious attack vectors: privilege escalation, arbitrary code execution, data manipulation as well as disclosure of sensitive information. The extent of the vulnerability depends on the specific context — some vulnerabilities require network access or existing permissions, others can be exploited from the outside.
CISOs should incorporate these updates with high priority into their patch processes, particularly for Azure infrastructures and Exchange environments, which often support critical business processes. Targeted attackers are likely to attempt to exploit these vulnerabilities in the near term.
Source: wid.cert-bund.de · Published 24 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.