Microsoft Discloses CVSS 10.0 Azure AI Foundry Flaw, Already Fixed

Microsoft published an advisory on 17 September 2026 for CVE-2026-85889, a flaw in Azure AI Foundry that its own security team scored at CVSS 10.0 — the maximum on the scale. The company's description is a single sentence: "Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network."
The severity comes from the vector Microsoft assigned, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. In plain terms, the Microsoft Security Response Center rated the weakness as reachable over the network, low in complexity, needing neither credentials nor any action by a user, and able to break out of its original security scope. It is classified as CWE-306, missing authentication for a critical function. Azure AI Foundry, which Microsoft also markets as Microsoft Foundry, is the platform enterprises use to build and run generative AI applications and agents.
Why the disclosure landed on 17 September rather than at the 8 September Patch Tuesday is a matter of how Microsoft handles its own cloud. Because Foundry is a service Microsoft operates, the fix shipped to the backend before the CVE existed. The advisory's FAQ states: "This vulnerability has already been fully mitigated by Microsoft. There is no action for users of this service to take. The purpose of this CVE is to provide further transparency." Microsoft's record marks the flaw as neither publicly disclosed nor exploited, and gives it a temporal score of 8.7 reflecting an official fix and unproven exploit code. MSRC credits independent researcher Rémy Marot with the report; The Hacker News gives his handle as @R_Marot.
It also was not alone. A count of Microsoft's September 2026 CVRF data shows 18 Microsoft cloud-service CVEs first published on 17 September, seven of them scored 10.0 — covering Azure Billing, Azure Arc, Microsoft Fabric, Microsoft Container Registry and Azure Logic Apps twice, alongside Foundry. Microsoft 365 Copilot and Azure Database for PostgreSQL were rated 9.9 the same day, Azure Cosmos DB 9.6, and a second, lower-rated Azure AI Foundry issue was filed as CVE-2026-85917 at 7.5. All 18 carry the same no-action-required note.
Two things remain open. The 10.0 is Microsoft's own figure as the CVE numbering authority: NVD listed the record on 17 September but still marks it "Awaiting Analysis," so no independent score exists yet. CISA's SSVC assessment on 18 September found no exploitation but classified the flaw as automatable with total technical impact. Microsoft has not named the vulnerable endpoint, and "no evidence of exploitation" is not the same as a forensic all-clear.
Sources
- Microsoft Security Response Center — CVE-2026-85889Primary source
- NIST National Vulnerability Database — CVE-2026-85889Primary source
- Microsoft MSRC — September 2026 Security Updates (CVRF)Primary source
- The Hacker NewsSecondary
- Cyber Security NewsSecondary
Related
WordPress 7.1.1 Patches Click2Shell: One Link Installs a Theme
BragJack: One Extension Hijacked AI Agents in 5 Browsers
Google Says Gemini Hacked Three Real Companies in May Test
Docker Sandboxes Flaw Rated 9.4 Let Code Escape to Mac Host
Plugin4Shell: 4 AI Coding Agents Hit, 2 Still Unpatched
Check Point Flaw Rated 9.8 Lets Attackers Run Code as Root
3 Linux Kernel Flaws Exploited; CISA Sets Sept. 21 Patch Deadline
Researchers Used Claude to Reach OpenAI Repos, Won $6,500
Trending now
- Claude Leads 26% of Anthropic's AI R&D, Up From 1% in March
- Google Says Gemini Hacked Three Real Companies in May Test
- OpenAI Sees $278B Cash Burn, $856B Compute Bill by 2030
- NASA Confirms McGetchin: 222-Meter Moon Crater Formed in 2024
- Sharks Feed on Beached Whale in Jamaica; NEPA Warns Swimmers
- Typhoon Dujuan Nears Tokyo at 965 hPa; JR East Halts Chiba Lines
- Anthropic Targets November IPO at About $2 Trillion Value
- NASA: Roman Telescope Has Fuel for 22 Years, Not 10
Comments
No comments yet. Be the first.