Home / Sep 19, 2026 / Story
0
#3 The Hacker News general September 18, 2026 at 12:47 UTC

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

By [email protected] (The Hacker News)

AI Summary

Microsoft patched CVE-2026-85889, a CVSS 10.0 privilege escalation flaw in Azure AI Foundry caused by missing authentication for a critical function, allowing unauthenticated network attackers to escalate privileges. Microsoft stated no customer action is required, indicating the fix was applied server-side, but the maximum severity score in a widely used AI development platform warrants attention from teams relying on Azure AI infrastructure.

Relevance score: 84.0/100

# More from September 19