CVE Tools

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

The Hacker NewsBy The Hacker News

PatchAzure AI FoundryMicrosoft 365 Copilot

Our summary

Microsoft remediated CVE-2026-85889 (CVSS 10.0) in Azure AI Foundry, where missing authentication could have allowed an unauthenticated remote attacker to elevate privileges. The company also mitigated CVE-2026-85885 in Microsoft 365 Copilot, CVE-2026-85878 in Azure Database for PostgreSQL, and CVE-2026-87701 in Azure Cosmos DB; these cloud issues require no customer action, and CVE-2026-85889 has not been seen exploited. An out-of-band Windows 11, version 26H1 update, KB5129194 (28000.2956), addresses CVE-2026-62721 in Windows User-Mode Power Service (UMPS) and CVE-2026-85921 in Windows Secure Kernel Mode, which could enable local privilege escalation.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store