DEV Community

Mark0
Mark0

Posted on

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

Microsoft has mitigated a critical vulnerability in Azure AI Foundry, tracked as CVE-2026-85889, which carried a maximum CVSS score of 10.0. This flaw could have allowed unauthorized attackers to achieve privilege escalation over a network. Microsoft also addressed high-severity vulnerabilities in Microsoft 365 Copilot, Azure Database for PostgreSQL, and Azure Cosmos DB, all of which required no user action as they were mitigated server-side.

In addition to cloud-based fixes, Microsoft released out-of-band updates for Windows 11 to patch local privilege escalation flaws in the User-Mode Power Service and Secure Kernel Mode. These updates are part of a massive patch cycle addressing nearly 1,000 vulnerabilities, some of which are already being leveraged in the wild through exploit kits like 'BlueMoon' to deliver malicious payloads.


Read Full Article

Top comments (0)