Microsoft Patches Critical Azure AI Foundry Flaw, Multiple Cloud Vulnerabilities
Microsoft has issued urgent fixes for a maximum-severity privilege escalation vulnerability in its Azure AI Foundry, alongside several other critical flaws affecting Azure services. While no customer action is required for the cloud-based vulnerabilities, these patches underscore the continuous security challenges within enterprise AI and cloud infrastructure.

**Microsoft** has rolled out crucial security updates addressing a critical flaw in **Azure AI Foundry** that could lead to privilege escalation. The vulnerability, identified as **CVE-2026-85889**, boasts a CVSS score of 10.0, indicating its maximum severity.
According to Microsoft's advisory, the flaw stems from "Missing authentication for critical function in Azure AI Foundry," allowing an unauthorized attacker to gain elevated privileges over a network. **Azure AI Foundry**, also known as **Microsoft Foundry**, is an enterprise platform designed for building, deploying, and managing generative AI applications and agents.
Security researcher **RΓ©my Marot (@R_Marot)** is credited with discovering and reporting the vulnerability. Fortunately, there is no current evidence of the issue being exploited in the wild.
### Additional Critical Cloud Vulnerabilities Addressed
Beyond the Azure AI Foundry flaw, Microsoft has also patched several other critical vulnerabilities impacting its cloud services:
* **CVE-2026-85885** (CVSS: 9.9): A command injection vulnerability in **Microsoft 365 Copilot** that could enable an authorized attacker to elevate privileges over a network.
* **CVE-2026-85878** (CVSS: 9.9): An improper authorization flaw in **Azure Database for PostgreSQL** that could allow an authorized attacker to elevate privileges over a network.
* **CVE-2026-87701** (CVSS: 9.6): An improper neutralization vulnerability in **Azure Cosmos DB** that could grant an authorized attacker elevated privileges over a network.
As is common with cloud-based **CVEs**, Microsoft confirms that these vulnerabilities have already been fully mitigated, meaning no action is required from users.
### Out-of-Band Updates for Windows 11
Separately, Microsoft has released out-of-band updates for two other vulnerabilities, one of which was initially disclosed last month:
* **CVE-2026-62721** (CVSS: 7.8): An insufficient granularity of access control in **Windows User-Mode Power Service (UMPS)**, potentially allowing an authorized attacker to achieve local privilege escalation to **SYSTEM** privileges.
* **CVE-2026-85921** (CVSS: 8.2): A double free vulnerability in **Windows Secure Kernel Mode** that could permit an authorized attacker to elevate privileges locally and gain **Virtual Trust Level 1 (VTL1)** privileges.
These flaws have been addressed as part of a cumulative update for **Windows 11, version 26H1**, specifically **KB5129194** for both arm64-based and x64-based systems.
### Context: Recent Exploitations and Broader Threat Landscape
These recent patches follow a record-breaking week where Microsoft addressed 974 vulnerabilities across its software portfolio. Notably, two of these, affecting **Windows Advanced Local Procedure Call (ALPC)** and the **Windows Update Stack**, have been actively exploited.
Reports from **Proofpoint** and **Volexity** indicate that the ALPC vulnerability has been chained with two **Google Chrome** flaws to create an exploit kit dubbed **BlueMoon**. This kit has been weaponized by multiple espionage-aligned threat actors to deliver malicious payloads, highlighting the sophisticated tactics employed by adversaries in the current threat landscape.