Microsoft Fixes CVSS 10.0 Flaw in Azure AI Foundry
Microsoft patched CVE-2026-85889, a CVSS 10.0 missing-authentication flaw in Azure AI Foundry that let unauthenticated attackers escalate privileges. No customer action required.

Microsoft disclosed and patched CVE-2026-85889 this week, a CVSS 10.0 critical vulnerability in Azure AI Foundry. The flaw is a missing-authentication condition on a critical function that let an unauthenticated attacker escalate privileges over a network, per the MSRC advisory. Microsoft applied the fix on the service side; no customer action is required.
Azure AI Foundry is Microsoft’s platform for building and deploying AI applications, including integrations with Azure OpenAI and other model endpoints. A privilege escalation in that environment has potential reach into AI workloads, API keys, and data stored within the platform. The MSRC advisory provides no technical detail beyond the vulnerability classification, which is standard for service-side fixes where the patch is already live before publication.
What to do
No patches to apply. If your organization runs workloads on Azure AI Foundry, review activity logs for anomalous access from the period before the patch date as a precaution. Microsoft has not published an exploitation window or confirmed active abuse.
Context
This disclosure lands alongside CVE-2026-69843, a CVSS 10.0 authentication bypass in Microsoft Fabric covered earlier today. Two separate Microsoft cloud services, both at maximum severity, both fixed server-side in the same disclosure cycle. That pattern is consistent with how Microsoft handles managed-service vulnerabilities: absorb the fix, then publish. It generally works in customers’ favor, though it also means the window between discovery and public disclosure is opaque from the outside.
Whether AI-development infrastructure is drawing more security-researcher attention than it used to is a reasonable question. The September Patch Tuesday roundup has additional context on the broader vulnerability volume Microsoft is processing right now. Also on the radar this week: Orkes Conductor’s CVSS 9.8 RCE in another cloud workflow platform, where active exploitation is confirmed.
- [ CRITICAL ]CVE-2026-85889Azure AI Foundry missing authentication allows unauthorized privilege escalation
Found this useful? Share it.


