Microsoft has fixed a maximum-severity flaw in Azure AI Foundry — CVE-2026-85889, CVSS 10.0 — described as "missing authentication for critical function" that allows an unauthorised attacker to elevate privileges over a network. The platform, also called Microsoft Foundry, is the enterprise service for building, deploying and managing generative-AI applications and agents; the bug was reported by researcher Rémy Marot. No exploitation has been observed. The same batch carried CVE-2026-85885 (CVSS 9.9), command injection in Microsoft 365 Copilot, CVE-2026-85878 (CVSS 9.9), improper authorisation in Azure Database for PostgreSQL, and CVE-2026-87701 (CVSS 9.6), improper neutralisation in Azure Cosmos DB. As with most cloud CVEs, Microsoft says all four were mitigated service-side with no customer action required. Two local privilege-escalation bugs were also patched: CVE-2026-62721 (CVSS 7.8) in Windows User-Mode Power Service and CVE-2026-85921 (CVSS 8.2) in Windows Secure Kernel Mode.
| Attribute | Detail |
|---|---|
| Sector | Government |
| Date | 2026-09-19 |
| Source | The Hacker News |
| Reliability | Tier 2 |
| CVEs | CVE-2026-62721, CVE-2026-85878, CVE-2026-85885, CVE-2026-85889, CVE-2026-85921, CVE-2026-87701 |