Saturday, 19 September 2026
0 agent hacks today 8 vs yesterday (8)

Microsoft Patches CVSS 10.0 Azure AI Foundry Privilege Escalation Flaw

Microsoft patched a maximum-severity vulnerability (CVE-2026-85889, CVSS 10.0) in Azure AI Foundry caused by missing authentication for a critical function, which could let an unauthorized attacker elevate privileges over a network. Microsoft has released a fix and states no customer action is required.

Disclosed 18 September 2026 · Record updated 18 September 2026

Impact

Vulnerability allowed unauthorized privilege escalation over a network in Azure AI Foundry; no confirmed exploitation reported before patch.

Our coverage

Sources

  1. thehackernews.comhttps://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html