Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-09-19 · updated: 2026-09-19 · tags: [incident, government] · confidence: high · severity: critical · affected_sectors: [government] · au_impact: true

Microsoft has fixed a maximum-severity flaw in Azure AI FoundryCVE-2026-85889, CVSS 10.0 — described as "missing authentication for critical function" that allows an unauthorised attacker to elevate privileges over a network. The platform, also called Microsoft Foundry, is the enterprise service for building, deploying and managing generative-AI applications and agents; the bug was reported by researcher Rémy Marot. No exploitation has been observed. The same batch carried CVE-2026-85885 (CVSS 9.9), command injection in Microsoft 365 Copilot, CVE-2026-85878 (CVSS 9.9), improper authorisation in Azure Database for PostgreSQL, and CVE-2026-87701 (CVSS 9.6), improper neutralisation in Azure Cosmos DB. As with most cloud CVEs, Microsoft says all four were mitigated service-side with no customer action required. Two local privilege-escalation bugs were also patched: CVE-2026-62721 (CVSS 7.8) in Windows User-Mode Power Service and CVE-2026-85921 (CVSS 8.2) in Windows Secure Kernel Mode.

Attribute Detail
Sector Government
Date 2026-09-19
Source The Hacker News
Reliability Tier 2
CVEs CVE-2026-62721, CVE-2026-85878, CVE-2026-85885, CVE-2026-85889, CVE-2026-85921, CVE-2026-87701