
Microsoft has patched a maximum-severity vulnerability in Azure AI Foundry — the enterprise platform for building, deploying, and managing generative AI applications and agents — that could have let unauthenticated attackers escalate their privileges over the network without any credentials. The flaw, tracked as CVE-2026-85889 with a CVSS score of 10.0, was caused by missing authentication for a critical function. Microsoft credited security researcher Rémy Marot for the discovery. There is no evidence of exploitation in the wild, and because Azure AI Foundry is a cloud-hosted service, Microsoft mitigated the vulnerability entirely on its own infrastructure — customers do not need to take any action.
Microsoft also patched three additional critical cloud service flaws in recent days: a command injection vulnerability in Microsoft 365 Copilot (CVE-2026-85885, CVSS 9.9), an improper authorization issue in Azure Database for PostgreSQL (CVE-2026-85878, CVSS 9.9), and an improper neutralization vulnerability in Azure Cosmos DB (CVE-2026-87701, CVSS 9.6). All four cloud CVEs are fully mitigated server-side and require no customer action. Separately, Microsoft released fixes for two Windows privilege-escalation flaws that do require a local Windows Update: CVE-2026-62721 (CVSS 7.8), an insufficient access control flaw in the Windows User-Mode Power Service (UMPS) that can elevate a local attacker to SYSTEM, and CVE-2026-85921 (CVSS 8.2), a double-free bug in Windows Secure Kernel Mode that can elevate to Virtual Trust Level 1 (VTL1).
How to check if you’re affected
Affected products include any Windows system running the Windows User-Mode Power Service (CVE-2026-62721) or Windows Secure Kernel Mode (CVE-2026-85921). Both require applying the latest Windows Update — check Settings → Windows Update and install any available patches. The four Azure cloud CVEs (Azure AI Foundry, Microsoft 365 Copilot, Azure Database for PostgreSQL, Azure Cosmos DB) are already remediated server-side; no customer action is needed for those.
