1. Executive summary
On 17 September 2026 Microsoft patched 18 vulnerabilities across its Azure cloud portfolio and Copilot-branded AI products, the majority of them elevation of privilege flaws. The most severe is CVE-2026-85889, a CVSS 10.0 missing-authentication flaw in Azure AI Foundry that allows an unauthorised attacker to elevate privileges over a network. Microsoft states all 18 fixes were applied server-side and that no customer action is required, and none of the vulnerabilities is flagged as exploited in the wild. A separate Windows privilege escalation fix, CVE-2026-85921, does require customers to patch, though Microsoft rates exploitation as less likely. EMEA financial services clients running Azure AI Foundry, Azure ARC, Logic Apps, Cosmos DB, Microsoft Fabric, Dataverse or Microsoft 365 Copilot should verify the server-side remediation in their tenants and treat the Windows update as a routine but time-bound patching action.
2. Regulatory framing
No specific DORA/NIS2 article is directly engaged by this item. The vulnerabilities were remediated by the vendor before publication, none is reported as exploited, and no incident has occurred at a client. Patching obligations under DORA Art. 24 (digital operational resilience testing, general requirements) and NIS2 Art. 21(2)(d) (supply chain security measures) apply to clients' own patch programmes generally, but no fact in this item creates a trigger distinctive to it, and no incident classification or reporting duty under DORA Art. 18 or Art. 19 arises without an incident.
3. Technical analysis & attack chain
This is a vendor patch release, not an observed attack, so there is no attack chain to reconstruct. The technical detail that matters to a defender is the set of affected components and the mechanics of the two named CVEs.
CVE-2026-85889 affects Azure AI Foundry. Microsoft's description states: "Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network." The CVSS score is 10.0, the maximum on the v3.1 scale, which is consistent with a network-reachable, unauthenticated, privileged operation. The Hacker News reports that no customer action is required because the fix was applied on Microsoft's side. The specific critical function left unauthenticated is not disclosed in the available material.
CVE-2026-85921 is a privilege escalation vulnerability affecting Windows. Unlike the Azure and Copilot set, this one requires users to update Windows. Microsoft's exploitability index assesses exploitation as "less likely". No further technical detail on the affected Windows components or the privilege boundary crossed is available in the source material.
The remaining 16 vulnerabilities break down as follows, per SecurityWeek:
- Elevation of privilege: Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Billing, Azure HorizonDB, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Microsoft Dataverse, and Microsoft 365 Copilot.
- Information disclosure: Copilot, Microsoft 365 Copilot, Microsoft 365 Copilot Business Chat, and Azure Machine Learning.
- Spoofing: a single flaw in Azure Portal.
Microsoft rated all 18 as critical by its severity taxonomy, but the underlying CVSS scores indicate high or medium severity for some of them. The verified reference data for this item resolved no per-CVE CVSS scores, KEV entries or EPSS values, so we do not rank the remaining 16 individually. Some flaws were found internally by Microsoft and many were reported by external researchers; the source does not name the researchers.
Two corroborating advisories confirm the Azure-wide scope. ANSSI's CERT-FR advisory of 15 July 2026 (CERTFR-2026-AVI-0871) covers multiple Azure vulnerabilities enabling remote code execution, elevation of privilege and remote denial of service. A second CERT-FR advisory dated 9 September 2026 (CERTFR-2026-AVI-1148) covers multiple Azure vulnerabilities enabling remote code execution, elevation of privilege and data confidentiality impact. BSI's WID-SEC-2026-2321 rates the Azure component set high and describes privilege elevation and denial of service. These advisories corroborate the impact classes but predate the 17 September release and do not enumerate the 18 CVEs covered here.
Context, not part of this release: Microsoft's July 2026 Patch Tuesday set a record of 622 CVEs including two zero-days under active attack, and the latest Patch Tuesday cycle fixed 970 vulnerabilities across Microsoft products. SecurityWeek attributes the surge in vulnerability discovery to increased use of advanced AI. None of the 18 vulnerabilities in this advisory is among the actively exploited July zero-days.
4. Mitigation & containment
P1 (within 24h): Verify that CVE-2026-85889 remediation is present in your Azure AI Foundry environments. Microsoft states the fix is server-side and no customer action is required, so the action is verification, not patching: confirm with your Microsoft account team or tenant health dashboards that no residual configuration is required, and review Azure AI Foundry access for unexplained privilege changes in the period before 17 September 2026. No exploitation has been reported, so no emergency containment is warranted.
P2 (within 72h): Patch Windows endpoints and servers for CVE-2026-85921 through your standard WSUS/Intune/Configuration Manager channels. Microsoft assesses exploitation as less likely, which places this in the routine queue rather than the emergency queue, but the 72-hour window is appropriate given it is a privilege escalation in a widely deployed operating system.
P3 (within 7 days): Record the 18-vendor-CVE release in your patch and vulnerability management registers against the affected services your organisation consumes: Azure ARC, Azure AI Foundry, Azure Logic Apps, Azure Billing, Azure HorizonDB, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Microsoft Dataverse, Microsoft 365 Copilot, Copilot, Microsoft 365 Copilot Business Chat, Azure Machine Learning and Azure Portal. For each, confirm the service is tenant-side managed where applicable and that no customer-deployed component (for example self-hosted Azure ARC agents or Azure Machine Learning compute) requires a version update; the source material does not state that any does, so this is a confirmation step, not a remediation step.
5. Indicators of compromise
No indicators of compromise available in the source material. No exploitation of any of these vulnerabilities has been reported, and the sources contain no hashes, domains, IPs or behavioural indicators.
6. Detection
Insufficient indicators to author detection rules. The sources describe vulnerabilities and vendor fixes, not threat artefacts: no strings, command lines, file paths, registry keys or log signatures appear in the material.
7. Sources
- SecurityWeek, "Microsoft Patches 18 Vulnerabilities in AI, Cloud Products", https://www.securityweek.com/microsoft-patches-18-vulnerabilities-in-ai-cloud-products/, 18 September 2026
- The Hacker News, "Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation", https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html, September 2026
- ANSSI France CERT, "Multiples vulnérabilités dans Microsoft Azure", https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0871/, 15 July 2026
- ANSSI France CERT, "Multiples vulnérabilités dans Microsoft Azure", https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1148/, 9 September 2026
- BSI Germany, "[NEU] [hoch] Microsoft Azure: Mehrere Schwachstellen", https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2321, 2026
- The Hacker News, "Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack", https://thehackernews.com/2026/07/microsoft-patches-record-622-flaws.html, July 2026
- SecurityWeek, "Microsoft, Apple Release Fresh Security Updates", https://www.securityweek.com/microsoft-apple-release-fresh-security-updates/, 2026
8. Adverse Trace position
We assess this release as low urgency for EMEA financial services clients despite the CVSS 10.0 headline, because the highest-severity flaw was fixed server-side before disclosure, none of the 18 vulnerabilities is reported as exploited, and the only customer-side action is a routine Windows update rated less likely to be exploited. The verified reference data resolved no per-CVE CVSS, KEV or EPSS values for this item, so our severity ranking rests on the vendor's own statements, and the CVSS 10.0 for CVE-2026-85889 is single-sourced to The Hacker News quoting Microsoft's description; verify the score against Microsoft's Security Update Guide before citing it in client risk registers. The concentration of privilege escalation flaws across Azure AI Foundry, Dataverse, Fabric and the Copilot family is a pattern worth tracking for clients building AI workloads on Azure, since it indicates where authentication boundaries in these services are still maturing. We will monitor for any post-disclosure exploitation reporting against CVE-2026-85889 or CVE-2026-85921 and will issue a follow-up note if either appears on CISA's KEV catalogue or in vendor incident reports.
Published via PulseTrace — Adverse Trace threat intelligence.