top of page

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

10 minutes ago
1 min read



In mid September 2026, Microsoft issued security fixes for a maximum severity vulnerability in Azure AI Foundry, the enterprise platform used to build, deploy, and manage generative artificial intelligence applications and autonomous agents. Tracked as CVE-2026-85889 with a maximum CVSS score of 10.0, the defect allows unauthenticated remote attackers to elevate privileges over network connections without requiring user interaction. 

  

Technical Details and Systemic Cloud Vulnerabilities

The underlying flaw stems from a missing authentication check on a critical management function within Azure AI Foundry. An attacker exploiting this vulnerability over a network connection can gain elevated privileges within the platform environment, potentially taking administrative control over hosted artificial intelligence models, pipeline configurations, and connected data sources. Discovered by security researcher Remy Marot, the flaw was disclosed alongside several other high severity cloud and AI vulnerabilities, including a command injection flaw in Microsoft 365 Copilot (CVE-2026-85885, CVSS 9.9), improper authorization in Azure Database for PostgreSQL (CVE-2026-85878, CVSS 9.9), and improper neutralization in Azure Cosmos DB (CVE-2026-87701, CVSS 9.6).   


Mitigation and Administrative Action

Because the vulnerability resides within Microsoft managed cloud infrastructure, the vendor applied server side mitigations across all hosted tenant environments. No evidence of active real world exploitation was detected prior to the patch rollout, and enterprise administrators are not required to take manual update actions for their cloud hosted instances. However, security teams utilizing hybrid or custom integrations with Azure AI Foundry should review internal API access logging to confirm no unauthorized requests targeted administrative endpoints prior to the mitigation deployment. 


Reference

 
 
 

Comments


Address: Office B322, Level 3, Spaces, Platinum Sentral, KL Sentral, 50470 Kuala Lumpur.

  • Facebook
  • Instagram
  • LinkedIn

Hotline+60327224705

© 2025 Vardaan Sdn Bhd. All Rights Reserved.

bottom of page