CVE-2026-85921
CVSS 8.2 HIGH: double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. EPSS 0.3% (18º percentile). Patch Microsoft: 5129194.
Patch disponibile KB5129194 Scarica →
Vulnerabilità ed exploit
Microsoft ha corretto 18 vulnerabilità tra Azure e Copilot, ma quasi tutto è stato chiuso lato server. Per Azure AI Foundry, Azure ARC, Azure Logic Apps, Azure Billing, Azure HorizonDB, Azure Cosmos DB, Azure Container Registry, Microsoft Fabric, Microsoft Dataverse, Microsoft 365 Copilot, Microsoft 365 Copilot Business Chat, Azure Machine Learning e Azure Database for PostgreSQL non c’è un fix cliente da distribuire.
L’unico intervento che resta in mano ai team è l’aggiornamento di Windows per CVE-2026-85921, la falla nel Windows Secure Kernel Mode. In pratica, il giro di Patch Tuesday si riduce a verificare lo stato delle macchine Windows 11 26H1; per il resto, Microsoft dice che le correzioni cloud sono già state applicate sui propri sistemi.
2 fonti · 18 set
CVSS 8.2 HIGH: double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. EPSS 0.3% (18º percentile). Patch Microsoft: 5129194.
Patch disponibile KB5129194 Scarica →
CVSS 10 CRITICAL: missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate…
The Hacker News
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Microsoft fixes a CVSS 10.0 Azure AI Foundry flaw enabling network privilege escalation; no exploitation has been observed.
originaleSecurityWeek
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.
originaleRiepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-09-18
Every edition of this story: Solo un fix cliente nel nuovo giro Microsoft