Vulnerabilities & Exploits

Microsoft Cloud Flaws Were Fixed Server-Side

Microsoft says 18 vulnerabilities across Azure, Copilot, and Windows were addressed this week, but only the Windows Secure Kernel flaw, CVE-2026-85921, needs a customer-installed update. The Azure and Copilot privilege-escalation issues, including CVE-2026-85889 in Azure AI Foundry, were already remediated on Microsoft’s side.

That means the cloud-side bugs were fixed in Microsoft’s services rather than by anything customers deploy. For operators, the practical consequence is narrow: Azure AI Foundry, Logic Apps, Cosmos DB, Fabric, Dataverse, and Copilot tenants do not have a separate patch to roll out for these issues, while Windows 11 26H1 systems still need the Secure Kernel update to close the local privilege-escalation path.

The lasting distinction is where the exposure lives. If your estate is mostly cloud services, Microsoft is carrying the fix; if you manage Windows endpoints, the Secure Kernel patch is the only item that still changes your risk.

2 sources · Sep 18

CVE-2026-85921

NVD KEV

CVSS 8.2 HIGH: double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. EPSS 0.3% (18th percentile). Microsoft patch: 5129194.

Patch available KB5129194 Download →

CVE-2026-85889

NVD KEV

CVSS 10 CRITICAL: missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate…

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-09-18

Every edition of this story: Microsoft Cloud Flaws Were Fixed Server-Side

More from today