Back to News
News · Cybersecurity

Microsoft Patches Maximum-Severity Azure AI Foundry Flaw

A CVSS 10.0 missing-authentication bug in Microsoft's enterprise AI platform could have let an unauthorized attacker escalate privileges over the network, no customer action required.

Source: The Hacker News · September 2026

The Hacker News reports that Microsoft has fixed a maximum-severity flaw, CVE-2026-85889 (CVSS 10.0), in Azure AI Foundry, the enterprise platform for building, deploying and managing generative AI applications and agents, also known as Microsoft Foundry. Microsoft described the issue as missing authentication for a critical function that would have allowed an unauthorized attacker to elevate privileges over a network. Security researcher Remy Marot was credited with discovering and reporting the flaw, which Microsoft says has already been fully mitigated with no evidence of exploitation and no action required from customers.

The fix shipped alongside two other high-severity patches in the same update: CVE-2026-85885 (CVSS 9.9), a command injection vulnerability in Microsoft 365 Copilot, and CVE-2026-87701 (CVSS 9.6), an improper neutralization vulnerability in Azure Cosmos DB.

Why it matters: as enterprises hand more autonomy and data access to AI platforms, an authentication gap at the platform level is a single point of failure with cloud-wide blast radius. Fast patch cycles and hardened identity controls around AI infrastructure are core to the security work we do for clients.