Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

Medium · The Hacker News ·

What happened

Microsoft patched CVE-2026-85889 (CVSS 10.0), a missing-authentication flaw in Azure AI Foundry allowing network privilege escalation; Microsoft says no customer action is required.

What to do now

Confirm Azure AI Foundry resources are patched; Microsoft states no customer action needed. Review Azure audit logs for anomalous privilege escalation, restrict network access to AI Foundry endpoints, and verify with the vendor advisory.

CVE references

  • CVE-2026-85889

Original source

The Hacker News

AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news