Threat · curated 18 Sep 2026

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

Coverage timeline

18 Sep 2026thehackernews.com

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

CVE-2026-85889 exposes an enterprise AI agent platform to unauthenticated privilege escalation, meaning a flaw in the AI build/deploy fabric itself could hand attackers control over generative-AI applications and agents.

Microsoft patched CVE-2026-85889, a maximum-severity (CVSS 10.0) flaw in Azure AI Foundry (Microsoft Foundry) caused by missing authentication for a critical function, allowing an unauthorized attacker to elevate privileges over a network. The platform is used to build, deploy, and manage generative AI applications and agents; no customer action is required and there is no evidence of in-the-wild exploitation. The flaw was reported by researcher Rémy Marot.