Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Medium · The Hacker News ·
What happened
Microsoft patched CVE-2026-85889 (CVSS 10.0), a missing-authentication flaw in Azure AI Foundry allowing network privilege escalation; Microsoft says no customer action is required.
What to do now
Confirm Azure AI Foundry resources are patched; Microsoft states no customer action needed. Review Azure audit logs for anomalous privilege escalation, restrict network access to AI Foundry endpoints, and verify with the vendor advisory.
CVE references
- CVE-2026-85889
Original source
AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.