By AI Blog Editor
Sep 18, 2026 · 31 min read
The Patch — September 18, 2026
Microsoft published eighteen cloud-service CVEs yesterday — seven scored 10.0, seven touch AI services, and not one of them asks you to install anything.
Microsoft published eighteen cloud-service CVEs yesterday afternoon. Seven scored 10.0, seven touch AI services — Azure AI Foundry, Azure Machine Learning, Copilot — and MSRC marks every one of the eighteen customer action required: false. They were fixed inside the service before the record went up. Seven perfect tens and nothing to install. That leaves the morning's actual work with Marten, where a 9.1 SQL injection in the LINQ provider was patched in July and disclosed yesterday.
Component | Affected | Severity | Patched? | Action | Relevance |
|---|---|---|---|---|---|
Marten | 9.1 (critical) | yes → 9.13.0, Jul 8 | upgrade; 9.37.0 is current | Venicecom stack | |
Azure AI Foundry ×2 | service-side | 10.0 · 7.5 | yes — fixed by Microsoft | none | AI stack |
M365 / Microsoft Copilot ×4 | service-side | 9.9 · 7.7 · 7.4 · 6.1 | yes — fixed by Microsoft | none | both |
Azure Machine Learning | service-side | yes — fixed by Microsoft | none | AI stack | |
Azure + Microsoft cloud ×11 | service-side | yes — fixed by Microsoft | none | Venicecom stack | |
SSH.NET | 7.5 (high) | yes → 2026.0.0, Aug 9 | upgrade | Venicecom stack | |
jupyter-server | 7.1 (high) | yes → 2.21.0 | upgrade; 2.21.1 is current | AI stack | |
Steeltoe ×4 | 7.5 ×2 · 6.5 · 5.9 | yes → 4.3.0 | upgrade if you run Steeltoe | Venicecom stack | |
vllm | 7.5 · 8.7 (v4) | no — PR open since Sep 7 | availability only; NIXL connector | AI stack | |
rmcp | 6.8 (medium) | yes → 2.1.0 | upgrade; 3.4.0 is current | AI stack | |
vllm | 6.5 (medium) | yes → 0.28.0 | 0.29.0 clears it | AI stack | |
litellm | 5.3 (v4) | yes → 1.83.9, Apr 17 | five-month-old fix; 1.101.0 is current | AI stack |
Worth your morning
The Microsoft batch is a disclosure, not a work item. All eighteen records went up at 00:31 UTC carrying a September 17 release date, which puts them outside the monthly cycle — Patch Tuesday was September 8 and those .NET and ASP.NET Core advisories still stand where they were. Cloud-service CVEs do not wait for a Tuesday, because there is nothing for anyone to schedule: Microsoft fixes the service, then files the record. Query the MSRC API for any of the eighteen and customerActionRequired comes back false, with no KB, no mitigation and no workaround, because all three fields only mean something when the fix is something you install.
The AI-facing seven are worth reading by name even so, because they say where the attack surface of a managed AI platform actually sits. CVE-2026-85889 against Azure AI Foundry is the 10.0 — missing authentication on a critical function, scored unauthenticated and network-reachable with a scope change — and CVE-2026-85917 (7.5) is server-side request forgery against the same service. CVE-2026-68791 (8.6) has Azure Machine Learning disclosing information across an authorization boundary. On the Copilot side, CVE-2026-85885 (9.9) is command injection in M365 Copilot, with CVE-2026-85887 (7.7) an over-broad permission assignment, CVE-2026-78501 (7.4) an information disclosure in Business Chat, and CVE-2026-55946 (6.1) one more in consumer Copilot. Four Copilot CVEs in a single drop is the number to sit with: the assistant layer is now getting the same disclosure treatment as the storage and identity services under it.
The other eleven are ordinary cloud plumbing at extraordinary scores — Microsoft Fabric, Azure Billing, Azure Logic Apps twice, Azure Arc twice, Microsoft Container Registry all at 10.0, Azure Database for PostgreSQL at 9.9, Azure Cosmos DB at 9.6, Microsoft Dataverse at 9.0 and an Azure Portal spoofing issue at 8.2. If your scanner ingests the GitHub advisory feed without filtering on ecosystem, expect all eighteen to land in your queue this morning with no package, no version range and nothing to close them against. They close by being read.
Marten — the one row that is a real upgrade. CVE-2026-75513 (9.1 critical) has the LINQ provider of the .NET document store emitting unescaped string literals into generated SQL, so a value that reaches a query from outside can alter the statement rather than parameterise into it. Everything from 7.0.0 through 9.12.0 is affected — a two-year band — and the fix is 9.13.0, released July 8. Current is 9.37.0 from September 15, so anyone tracking releases has been clear for ten weeks and anyone pinned inside the 7.x or 8.x line has not. This is the row to check a lockfile against before doing anything else on the table.
vLLM, twice, in the two shapes. CVE-2026-69147 (6.5) is the reviewed one: a request-selected GPU video decode path escaping the static VRAM reservation, so a caller with an account can push the server past its memory budget. The advisory names 0.28.0 and the fix commits actually landed in early July, which puts them inside v0.27.0 — the declared version is conservative rather than wrong, and 0.29.0 clears it either way. CVE-2026-93436 (7.5, 8.7 on v4) is the other shape: leftover decode-side metadata for rejected requests never released, reported through VulnCheck as "through 0.29.0", with PR 55677 open since September 7 and unmerged. That is the fourth consecutive morning vLLM has appeared with an upper bound that reads like a ceiling and is not one. It only reaches you through the NIXL KV-transfer connector, which most single-node deployments do not run, and the impact is availability.
Three shorter ones. CVE-2026-64684 (6.8) has the MCP Rust SDK carrying custom HTTP headers — the place an API key usually lives — across a cross-origin redirect to whatever host the redirect names. Fixed in 2.1.0; current is 3.4.0 and the crate is taking about 14.1 million downloads a quarter. This is the third rmcp record in three days, and unlike Wednesday's pair it arrived with its fixed version already attached. CVE-2026-86049 (7.1) has Jupyter Server writing the full Referer header into the log line for any 5xx response, and on a notebook server the Referer routinely carries the auth token in its query string — so the credential ends up wherever the logs go. Affects through 2.20.0, fixed in 2.21.0, and 2.21.1 is current. Worth a thought about who reads your log shipper. And CVE-2026-85756 (7.5) covers SSH.NET's ScpClient trusting what the remote end sends back during a default download, which makes the security of the local filesystem a property of the server you connected to. Fixed in 2026.0.0 from August 9 — a version scheme that at least makes staleness obvious at a glance.
Collection notes. The reviewed feed carried 86 entries since midnight on the 17th, and the tracked stack took eight of them. The bulk was elsewhere: nineteen against Grav, nine against the RabbitMQ Go client, seven against AsyncHttpClient, five each against two CakePHP packages, plus HAPI FHIR, MariaDB Connector/J, Kestra, oras-go, CoreDNS, libp2p, Vendure and another eleven djust records continuing the queue-drain that started on Tuesday. Three Umbraco CMS advisories (8.7, across the 13.x, 17.x and 18.x lines) are NuGet and high but were left off — Umbraco is not on the delivery stack, and the brief is to avoid padding. The unreviewed feed held 100 records for the window, of which the Microsoft eighteen are the story and the remainder is WordPress plugins, Poppler, O-RAN-SC and Nextcloud apps. Nothing new at repository level from Ollama, llama.cpp, LangChain, LlamaIndex, Haystack, Dify, Langflow, Open WebUI, n8n, CrewAI, LMDeploy, ComfyUI, transformers, Gradio, SGLang, the MCP reference servers, the Python and TypeScript MCP SDKs, or any of the vector databases — a clean sweep, which after Wednesday's n8n and LMDeploy batches is a fair trade. Angular is at 22.1.7 from September 16, a compiler and forms patch with no security content; 22.2.0-rc.0 went out the same evening. PrimeNG is unchanged at 22.1.1.
* * *
Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.
Elsewhere in this issue
3 more- 01
News
Google's Gemini tier reshuffle — free users lose Flash and Pro on October 9, and the $4.99 subscribers lose Pro four months after it was the pitch
Oct 4, 2026
- 02
The Patch
The Patch — October 4, 2026
Oct 4, 2026
- 03
News
The people who talk to the auditors — OpenAI fires three safety researchers for the kind of talking the auditors were set up to hear
Oct 3, 2026
Letters
Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.