Microsoft has fixed a maximum-severity security issue in Azure AI Foundry, its enterprise platform for developing and managing generative AI applications and agents. Microsoft Azure AI Foundry Vulnerability The attack vector is network-based, low-complex, and requires no privileges or user interaction, making it easily exploitable in theory, even though Microsoft has found no evidence of active exploitation or public proof-of-concept code circulating. This update includes several other significant fixes from Microsoft, including a command injection flaw in Microsoft 365 Copilot rated 9.9, and an improper authorization issue in Azure Database for PostgreSQL also rated 9.9, both of which could potentially grant elevated privileges over a network.
Microsoft also shipped an out-of-band update for Windows 11 version 26H1, addressing a Windows User-Mode Power Service flaw and a Secure Kernel Mode double-free bug that could grant SYSTEM or Virtual Trust Level 1 privileges. The Azure AI Foundry fix follows Microsoft's record-setting Patch Tuesday release last week, which addressed 974 vulnerabilities across its product portfolio, two of which are currently being exploited via an exploit kit called BlueMoon. While CVE-2026-85889 shows no signs of in-the-wild abuse, its critical severity and growing enterprise reliance on AI platforms highlight the importance of keeping an eye on Microsoft's security advisories, especially for cloud services where patching is handled entirely by the vendor.












