Critical Microsoft Azure AI Foundry Vulnerability Allows Attackers to Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Microsoft has patched a maximum-severity security flaw in Azure AI Foundry, its enterprise platform for building and managing generative AI applications and agents, that could have allowed an unauthenticated attacker to escalate privileges over the network without any user interaction.

Tracked as CVE-2026-85889, the vulnerability carries the highest possible CVSS score of 10.0, placing it among the most severe cloud security issues disclosed this year.

According to Microsoft’s advisory, published on September 17, 2026, the root cause is a missing authentication check for a critical function within Azure AI Foundry, classified under CWE-306.

This flaw meant an attacker with no valid credentials could reach and abuse a specific backend function, effectively bypassing the identity and access controls meant to gate privileged operations.

Microsoft Azure AI Foundry Vulnerability

Because the attack vector is network-based, low-complexity, and requires no privileges or user interaction, the flaw was rated as easily exploitable in theory, even though Microsoft has found no evidence of active exploitation or public proof-of-concept code circulating.

Azure AI Foundry, also called Microsoft Foundry, has rapidly become a central hub for enterprises deploying generative AI models, agents, and orchestration workflows.

A vulnerability of this nature in such a platform is particularly concerning because successful exploitation could grant an outsider the same level of control as a legitimate privileged user, potentially exposing sensitive AI models, training data, connected enterprise resources, or downstream systems integrated with Foundry-based applications.

Microsoft has credited security researcher Rémy Marot for discovering and responsibly disclosing the issue through its coordinated vulnerability disclosure program.

As is standard practice for cloud service vulnerabilities, Microsoft has already deployed a complete fix on the backend infrastructure. This means customers using Azure AI Foundry do not need to install patches, apply configuration changes, or take any other remediation steps; the issue is described as fully mitigated at the service level.

This disclosure arrives alongside several other critical Microsoft fixes issued in the same window, including CVE-2026-85885, a command injection flaw in Microsoft 365 Copilot rated 9.9, and CVE-2026-85878, an improper authorization issue in Azure Database for PostgreSQL also rated 9.9, both of which could similarly allow privilege escalation over a network.

Microsoft additionally shipped an out-of-band update for Windows 11 version 26H1 addressing a Windows User-Mode Power Service flaw and a Secure Kernel Mode double-free bug capable of granting SYSTEM or Virtual Trust Level 1 privileges.

The Azure AI Foundry fix follows closely on the heels of Microsoft’s record-setting Patch Tuesday release last week, which addressed 974 vulnerabilities across its product portfolio, two of which are already under active exploitation via an exploit kit dubbed BlueMoon.

While CVE-2026-85889 shows no signs of in-the-wild abuse, its critical severity and growing enterprise reliance on AI platforms underscore why organizations should keep monitoring Microsoft’s security advisories closely, even for cloud services where patching is handled entirely on the vendor handles patching entirely.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Critical Microsoft Azure AI Foundry Vulnerability Allows Attackers to Escalate Privileges appeared first on Cyber Security News.