Microsoft has announced the resolution of a critical security issue within its Azure AI Foundry platform, characterized as a high-severity vulnerability. The flaw, identified as CVE-2026-85889 and assigned a CVSS score of 10.0, allows unauthorized attackers to escalate privileges via network access. Microsoft has confirmed that no immediate action is required from users, as the issue has been fully addressed.
Details of the Azure AI Foundry Vulnerability
The Azure AI Foundry, also known as Microsoft Foundry, serves as an enterprise-level platform for the creation, deployment, and management of generative AI applications. A security advisory from Microsoft highlighted the absence of necessary authentication for a critical function within the platform, enabling potential privilege escalation by unauthorized entities.
Security researcher Rémy Marot, credited with discovering the flaw, reported the vulnerability, which has not been exploited in any known attacks. Microsoft’s swift response to this issue underscores its commitment to maintaining robust cloud security measures.
Additional Microsoft Vulnerability Patches
In addition to the Azure AI Foundry flaw, Microsoft has patched several other critical vulnerabilities across its software suite. These include CVE-2026-85885 and CVE-2026-85878, both with a CVSS score of 9.9, affecting Microsoft 365 Copilot and Azure Database for PostgreSQL, respectively. Another significant vulnerability, CVE-2026-87701, was identified in Azure Cosmos DB with a CVSS score of 9.6.
These vulnerabilities, typical of cloud-based security issues, have been mitigated without requiring user intervention. The consistent updates reflect Microsoft’s proactive approach to software security.
Recent Updates to Windows Vulnerabilities
Microsoft has also addressed two additional vulnerabilities impacting Windows systems. CVE-2026-62721 and CVE-2026-85921, affecting Windows User-Mode Power Service and Windows Secure Kernel Mode respectively, have been resolved. These issues, which allowed privilege escalation, were rectified through an out-of-band update for Windows 11, version 26H1.
The updates come shortly after Microsoft patched 974 vulnerabilities, two of which were actively exploited. The Advanced Local Procedure Call (ALPC) vulnerability was notably used in conjunction with Chrome flaws to create the BlueMoon exploit kit.
As Microsoft continues to enhance its security protocols, these updates reinforce the importance of timely software patching to protect against potential cyber threats.
