Search
Find merged stories by title or summary.
Critical Microsoft Azure AI Foundry Vulnerability Allows Attackers to Escalate Privileges
Microsoft has patched a maximum-severity security flaw in Azure AI Foundry, its enterprise platform for building and managing generative AI applications and agents, that could have allowed an unauthenticated attacker to escalate privileges over the network without any user interaction. Tracked as CVE-2026-85889 , the vulnerability carries the highest possible CVSS score of 10.0, placing it among the most severe cloud security issues disclosed this year. According to Microsoft’s advisory, published on September 17, 2026, the root cause is a missing authentication check for a critical function within Azure AI Foundry, classified under CWE-306. This flaw meant an attacker with no valid credentials could reach and abuse a specific backend function, effectively bypassing the identity and access controls meant to gate privileged operations.
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. "Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,"
CVE-2026-85889 Azure AI Foundry Elevation of Privilege Vulnerability
Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
You've reached the end of current stories for this search.
