CVE Tools
Back to feed

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

Microsoft remediated CVE-2026-85889 (CVSS 10.0) in Azure AI Foundry, where missing authentication could have allowed an unauthenticated remote attacker to elevate privileges. The company also mitigated CVE-2026-85885 in Microsoft 365 Copilot, CVE-2026-85878 in Azure Database for PostgreSQL, and CVE-2026-87701 in Azure Cosmos DB; these cloud issues require no customer action, and CVE-2026-85889 has not been seen exploited. An out-of-band Windows 11, version 26H1 update, KB5129194 (28000.2956), addresses CVE-2026-62721 in Windows User-Mode Power Service (UMPS) and CVE-2026-85921 in Windows Secure Kernel Mode, which could enable local privilege escalation.