Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Virginia governor creates an AI task force and moves to restrain data centers

    September 19, 2026

    An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.

    September 19, 2026

    CFTC Kicks Off Crypto Rulemaking, Bypassing a Stalled Congress

    September 19, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Virginia governor creates an AI task force and moves to restrain data centers
    • An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.
    • CFTC Kicks Off Crypto Rulemaking, Bypassing a Stalled Congress
    • On assisted dying, MPs grappled with a difficult bill | Assisted dying
    • Images of Gazan child before deadly airstrike are from real video, but likely AI-enhanced
    • Tata Sons: India’s corporate crown braces for upheaval amid boardroom revolt
    • How Germany’s far right learned to put on a smile to win elections – POLITICO
    • India forces caller-ID apps to feed spam reports to telcos
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, September 19
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 19, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananSep 18, 2026Vulnerability / Cloud Security

    Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required.

    The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0.

    “Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,” Microsoft said in a Thursday advisory.

    Azure AI Foundry, also called Microsoft Foundry, is an enterprise platform designed to build, deploy, and manage generative artificial intelligence (AI) applications and agents.

    The Windows maker credited security researcher Rémy Marot (@R_Marot) for discovering and reporting the flaw. There is no evidence that the issue has been exploited in the wild.

    Cybersecurity

    Also patched by Microsoft in recent days are a number of other critical flaws –

    • CVE-2026-85885 (CVSS score: 9.9) – A command injection vulnerability in Microsoft 365 Copilot that could allow an authorized attacker to elevate privileges over a network
    • CVE-2026-85878 (CVSS score: 9.9) – An improper authorization in Azure Database for PostgreSQL that could allow an authorized attacker to elevate privileges over a network
    • CVE-2026-87701 (CVSS score: 9.6) – An improper neutralization vulnerability in Azure Cosmos DB that could allow an authorized attacker to elevate privileges over a network

    As is typically the case with cloud-based CVEs, Microsoft said the vulnerabilities have already been fully mitigated, and that they require no action for users to take.

    Separately, Microsoft has shipped updates for two other vulnerabilities, one of which was originally disclosed last month.

    • CVE-2026-62721 (CVSS score: 7.8) – An insufficient granularity of access control in Windows User-Mode Power Service (UMPS) that could allow an authorized attacker to elevate privileges locally and gain SYSTEM privileges.
    • CVE-2026-85921 (CVSS score: 8.2) – A double free vulnerability in Windows Secure Kernel Mode that could allow an authorized attacker to elevate privileges locally and gain Virtual Trust Level 1 (VTL1) privileges.

    Both flaws have been addressed as part of an out-of-band update for Windows 11, version 26H1 –

    • 2026-09 Cumulative Update for Windows 11, version 26H1 for arm64-based Systems (KB5129194) (28000.2956)
    • 2026-09 Cumulative Update for Windows 11, version 26H1 for x64-based Systems (KB5129194) (28000.2956)

    The disclosure comes as Microsoft patched a record 974 vulnerabilities spanning its software portfolio earlier last week. Two of those defects impacting Windows Advanced Local Procedure Call (ALPC) and the Windows Update Stack have come under active exploitation.

    According to reports from Proofpoint and Volexity, the ALPC vulnerability has been chained along with two Google Chrome flaws to develop an exploit kit called BlueMoon that has been weaponized by multiple espionage-aligned threat actors to deliver malicious payloads.

    Azure CVSS Enabling Escalation Flaw Foundry Microsoft Patches Privilege unauthorized
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.

    OpenAI and Microsoft knew they were starting a ‘doom loop’ for the web

    23 Million User Records Compromised in Gyazo Data Breach 

    Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts

    New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

    Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Virginia governor creates an AI task force and moves to restrain data centers

    September 19, 2026

    An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.

    September 19, 2026

    CFTC Kicks Off Crypto Rulemaking, Bypassing a Stalled Congress

    September 19, 2026

    On assisted dying, MPs grappled with a difficult bill | Assisted dying

    September 19, 2026
    Latest Posts

    Texas deputy used 83K Flock cameras to find woman who had abortion. Was it a welfare check, as he claimed?

    August 4, 2026

    Trump’s Seabed Mining Order Is an Ecological and Political Disaster

    August 4, 2026

    ExxonMobil picks Sercel technology to support operations offshore Guyana

    August 4, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Virginia governor creates an AI task force and moves to restrain data centers

    September 19, 2026

    An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.

    September 19, 2026

    CFTC Kicks Off Crypto Rulemaking, Bypassing a Stalled Congress

    September 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.