#3
The Hacker News
general
September 18, 2026 at 12:47 UTC
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
By [email protected] (The Hacker News)
AI Summary
Microsoft patched CVE-2026-85889, a CVSS 10.0 privilege escalation flaw in Azure AI Foundry caused by missing authentication for a critical function, allowing unauthenticated network attackers to escalate privileges. Microsoft stated no customer action is required, indicating the fix was applied server-side, but the maximum severity score in a widely used AI development platform warrants attention from teams relying on Azure AI infrastructure.
Relevance score: 84.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →