Microsoft has released security fixes for a maximum severity vulnerability affecting Azure AI Foundry that could allow unauthorized privilege escalation. The flaw, tracked as CVE-2026-85889, carries a CVSS score of 10.0, the highest possible severity rating under the Common Vulnerability Scoring System. Microsoft confirmed that the issue has been addressed and stated that no customer action is required because the vulnerability has already been fully mitigated. There is currently no evidence that the flaw has been exploited in real-world attacks. According to Microsoft’s security advisory, the vulnerability involved missing authentication for a critical function in Azure AI Foundry, which could allow an unauthorized attacker to elevate privileges over a network. Azure AI Foundry, also known as Microsoft Foundry, is an enterprise platform that enables organizations to build, deploy, and manage generative artificial intelligence applications and AI agents. The platform is used by businesses to develop AI-powered solutions, making cloud security protections an important part of enterprise technology environments.
Microsoft credited security researcher Rémy Marot for discovering and responsibly reporting the vulnerability. The company’s response included fixes designed to prevent potential misuse of the flaw and strengthen security controls within the Azure AI Foundry environment. Alongside CVE-2026-85889, Microsoft also addressed several other high-severity vulnerabilities across its products. These included CVE-2026-85885, a command injection vulnerability in Microsoft 365 Copilot with a CVSS score of 9.9 that could allow an authorized attacker to elevate privileges over a network. Another issue, CVE-2026-85878, involved improper authorization in Azure Database for PostgreSQL and carried a CVSS score of 9.9. Microsoft also patched CVE-2026-87701, an improper neutralization vulnerability affecting Azure Cosmos DB that received a CVSS score of 9.6.
The company noted that cloud-based vulnerabilities addressed through its security updates have already been mitigated, reducing the need for additional steps from customers. Microsoft also released updates for other security issues, including CVE-2026-62721, an insufficient granularity of access control vulnerability affecting Windows User-Mode Power Service (UMPS), and CVE-2026-85921, a double free vulnerability in Windows Secure Kernel Mode. These vulnerabilities could allow authorized attackers to gain elevated privileges locally. Both issues were addressed through an out-of-band update for Windows 11 version 26H1, covering arm64-based systems and x64-based systems through the KB5129194 security update.
The latest security updates follow Microsoft’s recent patching of hundreds of vulnerabilities across its software portfolio. Earlier updates addressed 974 security flaws, including issues affecting Windows Advanced Local Procedure Call (ALPC) and the Windows Update Stack that were reported to have active exploitation activity. Security researchers have linked the ALPC vulnerability with other browser vulnerabilities to create exploit chains used by multiple espionage-aligned threat groups for delivering malicious payloads. Reports from security firms Proofpoint and Volexity highlighted how these vulnerabilities were combined with Google Chrome flaws to develop an exploit kit known as BlueMoon. Microsoft’s continued security updates highlight the importance of timely patch management and maintaining strong security practices across cloud and enterprise environments as organizations increasingly adopt artificial intelligence platforms and connected services.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





