> ## Content Index
> Fetch the complete content index at: https://f4n6.co.uk/llms.txt
> Use this file to discover other available public pages before exploring further.

# Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
- URL: https://f4n6.co.uk/security-feed/microsoft-patches-cvss-10-0-azure-ai-foundry-flaw-enabling-unauthorized-privilege-escalation/
- Published: 2026-09-19T17:50:30.000Z
- Updated: 2026-09-19T17:50:30.000Z
- Author: Jeff Davies
- Tags: #security-feed, CVE-2026-85889

## 1\. Executive summary

Microsoft has patched CVE-2026-85889, a CVSS 10.0 CRITICAL missing-authentication flaw (CWE-306) in Azure AI Foundry that allows an unauthenticated attacker to elevate privileges over a network. The vulnerability is NOT in CISA KEV and Microsoft states there is no evidence of in-the-wild exploitation; the vendor further states the flaw is already fully mitigated on its side and no customer action is required. Azure AI Foundry (also marketed as Microsoft Foundry) is the platform many banks and insurers are using to build and host generative AI applications and agents, so the exposure is at the AI application tier rather than at core banking infrastructure. The same patch cycle closed three further high-severity cloud flaws (CVE-2026-85885 in Microsoft 365 Copilot, CVE-2026-85878 in Azure Database for PostgreSQL, CVE-2026-87701 in Azure Cosmos DB) plus two Windows local privilege escalation bugs shipped out-of-band in KB5129194\. Clients should treat this as a verification and assurance exercise, not an emergency patch push.

## 2\. Regulatory framing

| Article                                                                 | Trigger (the fact in this item)                                                                                                                                                                                                                                                             | Practical impact                                                                                                                                                                                                                                                                 |
| ----------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| DORA Art. 28: ICT third-party risk — general principles                 | The vulnerable component is a third-party managed service (Microsoft Azure AI Foundry) where remediation was executed entirely by the provider and the client cannot patch it; the client's only available control is verifying the provider's mitigation and its own tenant configuration. | Financial entities using Foundry should record the flaw and Microsoft's mitigation statement in the ICT third-party risk register for the Microsoft relationship, and obtain/confirm the provider's remediation confirmation through the contract's information-sharing channel. |
| DORA Art. 18: classification of ICT-related incidents and cyber threats | A CVSS 10.0 unauthenticated privilege escalation path in a service the entity uses constitutes a cyber threat that must be classified under the entity's incident and threat classification criteria, even though no incident has occurred.                                                 | Classify the flaw against your DORA classification thresholds; if it does not meet major-incident criteria (no exploitation evidence, vendor-mitigated), document the classification decision and rationale.                                                                     |

No NIS2 or UK NIS article is engaged by a fact distinctive to this item. The absence of exploitation evidence and the vendor-side mitigation mean no incident reporting trigger under NIS2 Art. 23 or the UK NIS 2018 OES/RDSP duties arises from the material provided.

## 3\. Technical analysis & attack chain

**Vulnerability mechanism.** CVE-2026-85889 is a missing authentication for critical function flaw (CWE-306, per NVD) in Azure AI Foundry. Microsoft's advisory text: "Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network." The CVSS 10.0 score reflects an unauthenticated, network-reachable vector with no user interaction. The source does not disclose which Foundry API endpoint or control-plane function lacked authentication, so we cannot specify the exact request path or the privilege boundary crossed. The flaw was discovered and reported by security researcher Rémy Marot (@R\_Marot).

**Attack chain (reconstructed, not observed).** No exploitation has been observed; Microsoft states there is no evidence of in-the-wild exploitation. The chain below is the theoretical path implied by the vulnerability class:

1. Attacker reaches an unauthenticated Foundry endpoint or critical function exposed over the network.
2. The function executes without validating the caller's identity or authorisation level.
3. The attacker's context is elevated, granting privileges over Foundry resources (the source does not specify whether this means tenant-level, project-level, or agent/model-level privileges).
4. With elevated privileges, the attacker could act on the victim's AI assets: applications, agents, deployed models, or connected data sources. The source does not confirm which assets were reachable post-escalation.

**Remediation state.** Microsoft states the cloud-side vulnerabilities in this cycle, including CVE-2026-85889, have already been fully mitigated and require no customer action. This is consistent with Microsoft's standard handling of cloud service CVEs, where the fix is applied in the service rather than shipped to customers.

**Same-cycle flaws.** Microsoft also patched:

- CVE-2026-85885 (CVSS 9.9): command injection in Microsoft 365 Copilot; an authorised attacker elevates privileges over a network.
- CVE-2026-85878 (CVSS 9.9): improper authorisation in Azure Database for PostgreSQL; an authorised attacker elevates privileges over a network.
- CVE-2026-87701 (CVSS 9.6): improper neutralisation in Azure Cosmos DB; an authorised attacker elevates privileges over a network.

All three are vendor-mitigated with no customer action required, per Microsoft. Note that these three require an authenticated attacker, unlike CVE-2026-85889.

**Out-of-band Windows updates.** Separately, Microsoft shipped KB5129194 (build 28000.2956) for Windows 11 version 26H1 (arm64 and x64), fixing:

- CVE-2026-62721 (CVSS 7.8): insufficient granularity of access control in Windows User-Mode Power Service (UMPS); local privilege escalation to SYSTEM.
- CVE-2026-85921 (CVSS 8.2): double free in Windows Secure Kernel Mode; local privilege escalation to Virtual Trust Level 1 (VTL1).

CVE-2026-62721 was originally disclosed last month, per the source.

**Context.** This disclosure follows Microsoft's patching of a record 974 vulnerabilities the previous week, two of which (a Windows Advanced Local Procedure Call flaw and a Windows Update Stack flaw) are under active exploitation. Proofpoint and Volexity report the ALPC vulnerability has been chained with two Google Chrome flaws into an exploit kit called BlueMoon, used by multiple espionage-aligned threat actors to deliver payloads. Those flaws are outside this advisory's scope but inform the P2 recommendation below.

**Confidence caveat.** The technical description of CVE-2026-85889 rests on a single vendor advisory summarised by one outlet (The Hacker News). The ANSSI CERT advisories in the corpus (CERTFR-2026-AVI-0871, -0953, -1003, -1148) confirm only that multiple Azure vulnerabilities enabling privilege escalation, remote code execution, and data confidentiality impact were disclosed across July to September 2026; they do not name CVE-2026-85889 specifically. No second source describes the Foundry flaw's mechanism in more detail. Single-sourced; verify against Microsoft's own advisory before enforcement action.

## 4\. Mitigation & containment

### P1 — within 24 hours

- Confirm with your Azure tenant and platform teams whether Azure AI Foundry / Microsoft Foundry is used anywhere in the organisation, including under other licensing names (Microsoft Foundry), and obtain Microsoft's mitigation confirmation for CVE-2026-85889 from the vendor's advisory and support channel. No patch exists for customers to apply; the control is verification.
- If Foundry is in use, review Foundry audit and activity logs for the period before the mitigation date for unexplained privilege elevation, unusual agent or project creation, or access by unrecognised principals. The source gives no IOCs, so this is a configuration-and-log review, not a hunt for known artefacts.

### P2 — within 72 hours

- Apply KB5129194 (build 28000.2956) to all Windows 11 version 26H1 endpoints (arm64 and x64) to close CVE-2026-62721 and CVE-2026-85921\. These are local privilege escalation flaws requiring local access, but CVE-2026-62721 grants SYSTEM and CVE-2026-85921 grants VTL1, so they are useful post-compromise steps for any attacker with a foothold.
- Review the three authenticated-attacker cloud flaws (CVE-2026-85885 in Microsoft 365 Copilot, CVE-2026-85878 in Azure Database for PostgreSQL, CVE-2026-87701 in Azure Cosmos DB) against your usage of those services. Because they require an authorised attacker, the relevant control is least-privilege review of who holds Copilot, PostgreSQL, and Cosmos DB roles in your tenants, and removal of standing privileged access.
- Given the reported BlueMoon exploit kit chaining the actively exploited Windows ALPC flaw with Chrome flaws, confirm endpoint patch levels for Windows and Chrome and that EDR coverage is current on all internet-facing workstations.

### P3 — within 7 days

- Document the classification decision for CVE-2026-85889 under your DORA Art. 18 process, including the rationale for not treating it as a major incident (vendor-mitigated, no exploitation evidence).
- Update your Microsoft third-party risk register entry with this patch cycle and the vendor's no-action-required statement, and set a review point to confirm Microsoft's mitigation claim through your contractual information channel.
- If Foundry-hosted AI agents connect to internal data sources, verify those connections use scoped, least-privilege credentials so that a hypothetical privilege escalation in the platform cannot cascade into broader data access. The source does not describe the post-escalation blast radius, so this is precautionary hardening, not a confirmed requirement.

## 5\. Indicators of compromise

No indicators of compromise available in the source material.

No behavioural indicators are described in the sources beyond the generic privilege-elevation class of the flaw.

## 6\. Detection

Insufficient indicators to author detection rules.

The sources contain no strings, file paths, registry keys, command lines, or network artefacts belonging to the threat. CVE identifiers and product names are not threat artefacts and cannot support a rule.

## CVE assessment

1 referenced CVE — 1 critical (CVSS ≥ 9.0)

| CVE                                                                              | CVSS          | Exploited | EPSS | Summary                                                                                                                          |
| -------------------------------------------------------------------------------- | ------------- | --------- | ---- | -------------------------------------------------------------------------------------------------------------------------------- |
| [CVE-2026-85889](https://nvd.nist.gov/vuln/detail/CVE-2026-85889?ref=f4n6.co.uk) | 10.0 Critical | —         | —    | Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a n… |

## 7\. Sources

- The Hacker News, "Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation", https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html, 2026-09-18
- SecurityWeek, "Microsoft Patches 18 Vulnerabilities in AI, Cloud Products", https://www.securityweek.com/microsoft-patches-18-vulnerabilities-in-ai-cloud-products/, 2026-09 (corpus copy undated; confirms 18 flaws across Azure and AI-branded products, privilege escalation predominant)
- ANSSI France CERT, "Multiples vulnérabilités dans Microsoft Azure", CERTFR-2026-AVI-0871, https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0871/, 2026-07-15
- ANSSI France CERT, "Vulnérabilité dans Microsoft Azure", CERTFR-2026-AVI-0953, https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0953/, 2026-07-31
- ANSSI France CERT, "Multiples vulnérabilités dans Microsoft Azure", CERTFR-2026-AVI-1003, https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1003/, 2026-08-12
- ANSSI France CERT, "Multiples vulnérabilités dans Microsoft Azure", CERTFR-2026-AVI-1148, https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1148/, 2026-09-09

## 8\. Adverse Trace position

We assess CVE-2026-85889 as a maximum-severity flaw by CVSS (10.0 CRITICAL, per NVD) but with low current exploitability to clients: it is not in CISA KEV, Microsoft reports no evidence of in-the-wild exploitation, and the vendor states the flaw is already fully mitigated server-side with no customer action required. The practical risk to EMEA financial services is therefore assurance risk rather than immediate compromise risk: entities building generative AI applications and agents on Azure AI Foundry should confirm the mitigation, review pre-mitigation tenant logs, and record the event under their DORA Art. 18 classification and Art. 28 third-party risk processes. The technical mechanism is single-sourced from one vendor advisory as reported by one outlet, and we flag that attribution of any future exploitation would be unconfirmed until corroborated. We will monitor for any exploitation reporting against CVE-2026-85889, for CISA KEV listing, and for Microsoft's September 2026 patch-cycle documentation covering the companion flaws, and we will reissue this advisory if the no-action-required position changes.

---

[Read the original source →](https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html?ref=f4n6.co.uk)

*Published via PulseTrace — Adverse Trace threat intelligence.*