Ethical Hacking News
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry, enabling unauthorized privilege escalation, as well as other critical flaws in Microsoft 365 and Windows. The company has stated that no customer action is required, and the vulnerabilities have already been fully mitigated.
Microsoft has patched critical security vulnerabilities in Azure AI Foundry, Microsoft 365, and Windows platforms. Top priority was given to CVE-2026-85889, a maximum-severity security flaw in Azure AI Foundry that enables unauthorized privilege escalation. Patches have also been released for other critical flaws, including command injection vulnerabilities in Microsoft 365 Copilot and improper authorization issues in Azure Database for PostgreSQL and Azure Cosmos DB. A total of 974 vulnerabilities have been patched by Microsoft across its software portfolio in recent months. Some of these vulnerabilities have been exploited by threat actors, including the ALPC vulnerability in Windows Advanced Local Procedure Call (ALPC) and Windows Update Stack.
Microsoft, the renowned technology giant, has taken swift action to address a multitude of critical security vulnerabilities in its Azure AI Foundry, Microsoft 365, and Windows platforms. The recent patches, which were released as part of the company's ongoing commitment to ensuring the security and integrity of its products, target a range of flaws that could potentially be exploited by malicious actors.
The most pressing of these vulnerabilities is CVE-2026-85889, a maximum-severity security flaw in Azure AI Foundry that enables unauthorized privilege escalation. This vulnerability, which carries a CVSS score of 10.0, was discovered by security researcher Rémy Marot (@R_Marot) and has been fully mitigated by Microsoft. The company has stated that no customer action is required, and the vulnerability has not been exploited in the wild.
In addition to the Azure AI Foundry vulnerability, Microsoft has also patched a number of other critical flaws, including CVE-2026-85885 (CVSS score: 9.9), a command injection vulnerability in Microsoft 365 Copilot that could allow an authorized attacker to elevate privileges over a network. Furthermore, CVE-2026-85878 (CVSS score: 9.9) and CVE-2026-87701 (CVSS score: 9.6) have also been addressed, with the latter two vulnerabilities related to improper authorization in Azure Database for PostgreSQL and Azure Cosmos DB, respectively.
Microsoft has also shipped updates for two other vulnerabilities, CVE-2026-62721 (CVSS score: 7.8) and CVE-2026-85921 (CVSS score: 8.2), which were originally disclosed last month. These vulnerabilities relate to insufficient granularity of access control in Windows User-Mode Power Service (UMPS) and a double free vulnerability in Windows Secure Kernel Mode, respectively.
The disclosure of these vulnerabilities comes on the heels of Microsoft's recent patching of a record 974 vulnerabilities spanning its software portfolio. Two of these defects, impacting Windows Advanced Local Procedure Call (ALPC) and the Windows Update Stack, have already come under active exploitation.
According to reports from Proofpoint and Volexity, the ALPC vulnerability has been chained along with two Google Chrome flaws to develop an exploit kit called BlueMoon that has been weaponized by multiple espionage-aligned threat actors to deliver malicious payloads.
As the threat landscape continues to evolve, it is essential for organizations to stay vigilant and proactive in addressing emerging security vulnerabilities. Microsoft's commitment to regular patching and security updates is a testament to the company's dedication to ensuring the security and integrity of its products.
In conclusion, Microsoft's recent patches highlight the importance of ongoing security monitoring and patching. As the threat landscape continues to evolve, it is essential for organizations to stay informed and take proactive steps to protect themselves against emerging security vulnerabilities.
Related Information:
https://www.ethicalhackingnews.com/articles/Microsoft-Patches-Critical-Flaws-in-Azure-AI-Foundry-Microsoft-365-and-Windows-ehn.shtml
https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html
https://nvd.nist.gov/vuln/detail/CVE-2026-85889
https://www.cvedetails.com/cve/CVE-2026-85889/
https://nvd.nist.gov/vuln/detail/CVE-2026-85885
https://www.cvedetails.com/cve/CVE-2026-85885/
https://nvd.nist.gov/vuln/detail/CVE-2026-85878
https://www.cvedetails.com/cve/CVE-2026-85878/
https://nvd.nist.gov/vuln/detail/CVE-2026-87701
https://www.cvedetails.com/cve/CVE-2026-87701/
https://nvd.nist.gov/vuln/detail/CVE-2026-62721
https://www.cvedetails.com/cve/CVE-2026-62721/
https://nvd.nist.gov/vuln/detail/CVE-2026-85921
https://www.cvedetails.com/cve/CVE-2026-85921/
Published: Fri Sep 18 09:47:59 2026 by llama3.2 3B Q4_K_M