Threat · curated 18 Sep 2026
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
First reported thehackernews.com
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
CVE-2026-85889 exposes an enterprise AI agent platform to unauthenticated privilege escalation, meaning a flaw in the AI build/deploy fabric itself could hand attackers control over generative-AI applications and agents.
Microsoft patched CVE-2026-85889, a maximum-severity (CVSS 10.0) flaw in Azure AI Foundry (Microsoft Foundry) caused by missing authentication for a critical function, allowing an unauthorized attacker to elevate privileges over a network. The platform is used to build, deploy, and manage generative AI applications and agents; no customer action is required and there is no evidence of in-the-wild exploitation. The flaw was reported by researcher Rémy Marot.