CVE-2026-85921
CVSS 8.2 HIGH: double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. EPSS 0.3% (18th percentile). Microsoft patch: 5129194.
Patch available KB5129194 Download →
Vulnerabilities & Exploits
Microsoft says 18 vulnerabilities across Azure, Copilot, and Windows were addressed this week, but only the Windows Secure Kernel flaw, CVE-2026-85921, needs a customer-installed update. The Azure and Copilot privilege-escalation issues, including CVE-2026-85889 in Azure AI Foundry, were already remediated on Microsoft’s side.
That means the cloud-side bugs were fixed in Microsoft’s services rather than by anything customers deploy. For operators, the practical consequence is narrow: Azure AI Foundry, Logic Apps, Cosmos DB, Fabric, Dataverse, and Copilot tenants do not have a separate patch to roll out for these issues, while Windows 11 26H1 systems still need the Secure Kernel update to close the local privilege-escalation path.
The lasting distinction is where the exposure lives. If your estate is mostly cloud services, Microsoft is carrying the fix; if you manage Windows endpoints, the Secure Kernel patch is the only item that still changes your risk.
2 sources · Sep 18
CVSS 8.2 HIGH: double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. EPSS 0.3% (18th percentile). Microsoft patch: 5129194.
Patch available KB5129194 Download →
CVSS 10 CRITICAL: missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate…
The Hacker News
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Microsoft fixes a CVSS 10.0 Azure AI Foundry flaw enabling network privilege escalation; no exploitation has been observed.
originalSecurityWeek
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.
originalPart of the PlainSec briefing for 2026-09-18
Every edition of this story: Microsoft Cloud Flaws Were Fixed Server-Side