VulnerabilitiesMicrosoft fixes maximum-severity Azure AI Foundry flaw
The privilege escalation bug scored a perfect 10.0 on the CVSS severity scale, and Microsoft says customers do not need to take any action.
18 Sept 2026
Microsoft patched a maximum-severity vulnerability (CVE-2026-85889, CVSS 10.0) in Azure AI Foundry caused by missing authentication for a critical function, which could let an unauthorized attacker elevate privileges over a network. Microsoft has released a fix and states no customer action is required.
Disclosed 18 September 2026 · Record updated 18 September 2026
Vulnerability allowed unauthorized privilege escalation over a network in Azure AI Foundry; no confirmed exploitation reported before patch.
VulnerabilitiesThe privilege escalation bug scored a perfect 10.0 on the CVSS severity scale, and Microsoft says customers do not need to take any action.
18 Sept 2026