Security

Microsoft Patches CVSS 10.0 Flaw in Azure AI Foundry

The maximum-severity authentication bypass required no customer action as Microsoft mitigated the cloud vulnerability server-side.

Omega Editorial· September 18, 2026· 3 min read

Microsoft has addressed a maximum-severity security vulnerability in its Azure AI Foundry platform that could have allowed attackers to escalate privileges without authentication. The flaw, designated CVE-2026-85889, received a rare perfect CVSS score of 10.0.

The vulnerability stemmed from missing authentication for a critical function within Azure AI Foundry, Microsoft's enterprise platform for building and deploying generative AI applications. An unauthorized attacker exploiting the flaw could have elevated privileges over a network connection, according to Microsoft's Thursday advisory.

Security researcher Rémy Marot discovered and reported the issue. Microsoft stated it has found no evidence of exploitation in the wild, and because the vulnerability exists in cloud infrastructure, the company applied fixes server-side without requiring customer intervention.

Why it matters

A CVSS 10.0 rating represents the most severe classification possible, reserved for flaws that are trivially exploitable and carry catastrophic impact. In enterprise AI platforms handling sensitive data and model deployments, an authentication bypass of this nature could have granted attackers complete control over AI workloads, training data, and deployed models. The server-side mitigation demonstrates a key advantage of cloud services—critical vulnerabilities can be patched transparently without enterprise security teams scrambling to deploy updates.

Additional critical Azure and Microsoft 365 fixes

Microsoft simultaneously patched four other critical vulnerabilities across its cloud services:

  • CVE-2026-85885 (CVSS 9.9): A command injection flaw in Microsoft 365 Copilot allowing privilege escalation
  • CVE-2026-85878 (CVSS 9.9): Improper authorization in Azure Database for PostgreSQL enabling privilege escalation
  • CVE-2026-87701 (CVSS 9.6): Improper neutralization in Azure Cosmos DB that could lead to elevated privileges

All four cloud-based vulnerabilities have been fully mitigated by Microsoft without requiring customer action.

Windows kernel vulnerabilities addressed

Separately, Microsoft released out-of-band updates for Windows 11 version 26H1 addressing two local privilege escalation flaws:

  • CVE-2026-62721 (CVSS 7.8): Insufficient access control in Windows User-Mode Power Service allowing attackers to gain SYSTEM privileges
  • CVE-2026-85921 (CVSS 8.2): A double free vulnerability in Windows Secure Kernel Mode enabling attackers to obtain Virtual Trust Level 1 privileges

Both issues were resolved in cumulative update KB5129194, bringing Windows 11 26H1 to build 28000.2956 for both x64 and ARM64 systems.

Broader security context

These patches arrive shortly after Microsoft's record-setting September update that addressed 974 vulnerabilities across its product portfolio. Two flaws from that batch—affecting Windows Advanced Local Procedure Call and the Windows Update Stack—are already under active exploitation. Security firms Proofpoint and Volexity have observed threat actors chaining the ALPC vulnerability with Chrome exploits in an attack framework called BlueMoon, deployed by espionage-focused groups.

The details were first reported by The Hacker News.

#microsoft#azure#vulnerability#ai security#privilege escalation#cloud security

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

AI Models Easily Exploited to Create Election Misinformation at Scale

New testing reveals major chatbots and image generators consistently bypass safeguards to produce convincing false election content ahead of 2026 midterms.

Via AI Watch · Sep 18, 2026
Security· 3 min read

Agentic SOCs Need Memory and Accountability, Not Just Speed

AI-driven security operations centers must combine operational context, validated intelligence, and human oversight to make automation effective.

Via Automation Watch · Sep 18, 2026
Security· 3 min read

Security Researchers Breach OpenAI Using Anthropic's Claude

Ethical hackers exploited employee accounts and accessed code repositories, highlighting AI's dual role in cybersecurity threats.

Via AI Watch · Sep 18, 2026