AI Weekly Malaysia

Back to items Summaries

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

ID
25974
Status
summarized
Published
18 Sep 2026, 8:47 PM
Fetched
18 Sep 2026, 11:12 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
4.5
Created
18 Sep 2026, 11:15 PM
Tags
Audience
developersai_agent_usersdatabase_learners

What happened

Microsoft patched a CVSS 10.0 missing-authentication flaw (CVE-2026-85889) in Azure AI Foundry enabling network-based privilege escalation, plus three other critical cloud CVEs: a 9.9 command injection in Microsoft 365 Copilot (CVE-2026-85885), a 9.9 improper authorization in Azure Database for PostgreSQL (CVE-2026-85878), and a 9.6 improper neutralization in Azure Cosmos DB (CVE-2026-87701). All cloud flaws were mitigated server-side with no customer action required, and there is no evidence of in-the-wild exploitation. Microsoft also shipped an out-of-band Windows 11 26H1 update (KB5129194) for two local privilege escalation flaws (CVE-2026-62721 at 7.8 and CVE-2026-85921 at 8.2).

Why it matters

If you ship AI agents or apps on Azure AI Foundry, Copilot, Azure PostgreSQL, or Cosmos DB, these are now patched server-side so no immediate action is needed—but the cluster of CVSS 9.6–10.0 auth and injection flaws across Microsoft's AI and data platforms in one cycle is a signal to factor platform security maturity into your cloud provider choice. Windows 11 26H1 users should apply KB5129194 for the two local privilege escalation fixes.

Discussion angle

Four critical auth/injection flaws across Microsoft's AI and database platforms in a single patch cycle—does this change how you evaluate Azure for AI agent workloads versus AWS or GCP, or is it just the cost of a large platform surface area?

Top