Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
CVE Tools coverage
Microsoft remediated CVE-2026-85889 (CVSS 10.0) in Azure AI Foundry, where missing authentication could have allowed an unauthenticated remote attacker to elevate privileges. The company also mitigated CVE-2026-85885 in Microsoft 365 Copilot, CVE-2026-85878 in Azure Database for PostgreSQL, and CVE-2026-87701 in Azure Cosmos DB; these cloud issues require no customer action, and CVE-2026-85889 has not been seen exploited. An out-of-band Windows 11, version 26H1 update, KB5129194 (28000.2956), addresses CVE-2026-62721 in Windows User-Mode Power Service (UMPS) and CVE-2026-85921 in Windows Secure Kernel Mode, which could enable local privilege escalation.