"Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network," Microsoft said in a Thursday advisory.
CVE-2026-85889: Missing authentication in Azure AI Foundry
Microsoft released a fix for CVE-2026-85889, a maximum-severity vulnerability in Azure AI Foundry (also called Microsoft Foundry) that carries a CVSS score of 10.0. The company described the defect as a missing authentication for a critical function that could be exploited by an unauthorized attacker to elevate privileges over a network. Microsoft credited security researcher Rémy Marot (@R_Marot) for discovering and reporting the flaw, and said there is no evidence the issue has been exploited in the wild. Microsoft also stated that no customer action is required.
Other critical cloud flaws closed this week
Alongside the Foundry fix, Microsoft patched several other high‑severity cloud vulnerabilities in recent days:
- CVE-2026-85885 (CVSS 9.9) — a command injection vulnerability in Microsoft 365 Copilot that could allow an authorized attacker to elevate privileges over a network.
- CVE-2026-85878 (CVSS 9.9) — an improper authorization in Azure Database for PostgreSQL that could allow an authorized attacker to elevate privileges over a network.
- CVE-2026-87701 (CVSS 9.6) — an improper neutralization vulnerability in Azure Cosmos DB that could allow an authorized attacker to elevate privileges over a network.
As is typically the case for cloud‑hosted services, Microsoft said these vulnerabilities have already been fully mitigated on its side and require no action from customers.

Your scanner finds 4,000 vulns. Which 12 matter?
Nubivance is a Rapid7 Registered Partner delivering vulnerability management as a service - scanning, risk-based prioritization, and remediation follow-through across IT and OT.
Fix the backlogWindows out‑of‑band patches for local privilege escalations
Microsoft also shipped out‑of‑band updates addressing two Windows vulnerabilities:
- CVE-2026-62721 (CVSS 7.8) — an insufficient granularity of access control in Windows User‑Mode Power Service (UMPS) that could allow an authorized attacker to elevate privileges locally and gain SYSTEM privileges.
- CVE-2026-85921 (CVSS 8.2) — a double free vulnerability in Windows Secure Kernel Mode that could allow an authorized attacker to elevate privileges locally and gain Virtual Trust Level 1 (VTL1) privileges.
Both flaws were addressed as part of the out‑of‑band cumulative update for Windows 11, version 26H1 (KB5129194), listed with build number (28000.2956) for both arm64‑based and x64‑based systems.
Active exploitation context: ALPC, Windows Update Stack and the BlueMoon kit
The new disclosures arrive days after Microsoft released a record 974 fixes across its software portfolio. Two of the defects among that larger set — affecting Windows Advanced Local Procedure Call (ALPC) and the Windows Update Stack — have been reported to be under active exploitation. Industry reporting from Proofpoint and Volexity says the ALPC vulnerability has been chained with two Google Chrome flaws to create an exploit kit called BlueMoon, which has been weaponized by multiple espionage‑aligned threat actors to deliver malicious payloads.
What this means for security teams, enterprise IT, and adversaries
Security teams: Microsoft’s advisory stresses that cloud fixes — including the Foundry and other cloud CVEs listed above — are already mitigated and require no customer action. Teams should nevertheless validate logging and detection coverage for any signs of lateral movement tied to privilege‑escalation techniques and remain attentive to alerts tied to the ALPC and Windows Update Stack exploits noted by Proofpoint and Volexity.
Enterprise IT and procurement leaders: For organizations running Windows 11, version 26H1, the out‑of‑band KB5129194 updates address the two Windows local‑privilege flaws; patch deployment and verification of update status will determine whether endpoints are protected against the local escalation paths described.
Adversaries and threat actors: While Microsoft reports no evidence of exploitation for CVE-2026-85889, the presence of an exploit kit (BlueMoon) that chains ALPC and Chrome flaws demonstrates how attackers combine multiple defects. That pattern makes high‑severity fixes a potential focus for reuse or chaining in future campaigns.
Microsoft’s latest round of patches closes a maximum‑severity bug in an AI application platform, several near‑critical cloud defects, and local privilege holes in Windows — and the company says customers need do nothing further for the cloud fixes. The simultaneous reality that two previously patched Windows defects are under active exploitation, and that researchers have observed those defects weaponized in the BlueMoon kit, underscores a simple operational fact: fixes are necessary and, in Microsoft’s account, in place — but defenders must still confirm deployment and monitor for active chains that weaponize other flaws.




