Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

Summary

Microsoft has patched a critical vulnerability in Azure AI Foundry, identified as CVE-2026-85889, which had a CVSS score of 10.0. This flaw allowed unauthorized attackers to escalate privileges over a network. No customer action is required as Microsoft has already implemented the fixes.

IFF Assessment

FOE

This is bad news for defenders as a critical vulnerability with maximum severity has been discovered and exploited, allowing unauthorized privilege escalation.

Severity

10.0 Critical

Defender Context

Defenders should be aware of critical vulnerabilities in cloud AI platforms like Azure AI Foundry, especially those with high CVSS scores that enable privilege escalation. It highlights the importance of timely patching and robust authentication mechanisms for critical functions within AI infrastructure.

Read Full Story →