Microsoft: Critical Microsoft Azure AI Foundry Vulnerability Allows Attackers to Escalate Privileges

Microsoft: Critical Microsoft Azure AI Foundry Vulnerability Allows Attackers to Escalate Privileges

Critical Azure AI Foundry Vulnerability Patched by Microsoft

Microsoft has resolved a maximum-severity security flaw (CVE-2026-85889) in Azure AI Foundry, its enterprise platform for generative AI applications, that could have allowed unauthenticated attackers to escalate privileges over the network without user interaction. The vulnerability, assigned a CVSS score of 10.0, stems from a missing authentication check (CWE-306) in a critical backend function, enabling attackers to bypass access controls and gain privileged access.

Disclosed on September 17, 2026, the flaw was deemed highly exploitable due to its low complexity and network-based attack vector. However, Microsoft reported no evidence of active exploitation or public proof-of-concept code. Given Azure AI Foundry’s role as a central hub for AI model deployment, successful exploitation could have exposed sensitive AI models, training data, and integrated enterprise systems.

Security researcher Rémy Marot discovered the issue, which Microsoft addressed via a backend fix requiring no customer action. The patch coincides with other critical fixes, including a 9.9-rated command injection flaw in Microsoft 365 Copilot (CVE-2026-85885) and a 9.9-rated improper authorization issue in Azure Database for PostgreSQL (CVE-2026-85878), both capable of network-based privilege escalation.

The disclosure follows Microsoft’s record-breaking Patch Tuesday, which addressed 974 vulnerabilities, two of which are already under active exploitation via the BlueMoon exploit kit. While CVE-2026-85889 remains unexploited, its severity highlights risks in AI-driven enterprise platforms.

Source: https://cybersecuritynews.com/microsoft-azure-ai-foundry-vulnerability/

Microsoft TPRM report: https://www.rankiteo.com/company/microsoft-ai

"id": "mic1789743686",
"linkid": "microsoft-ai",
"type": "Vulnerability",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Technology/Cloud Services',
                        'name': 'Microsoft Azure AI Foundry',
                        'type': 'Enterprise AI Platform'}],
 'attack_vector': 'Network',
 'data_breach': {'sensitivity_of_data': 'High',
                 'type_of_data_compromised': 'AI models, training data, '
                                             'enterprise system data'},
 'date_publicly_disclosed': '2026-09-17',
 'description': 'Microsoft has resolved a maximum-severity security flaw '
                '(CVE-2026-85889) in Azure AI Foundry, its enterprise platform '
                'for generative AI applications, that could have allowed '
                'unauthenticated attackers to escalate privileges over the '
                'network without user interaction. The vulnerability, assigned '
                'a CVSS score of 10.0, stems from a missing authentication '
                'check (CWE-306) in a critical backend function, enabling '
                'attackers to bypass access controls and gain privileged '
                'access.',
 'impact': {'data_compromised': 'Sensitive AI models, training data, '
                                'integrated enterprise systems',
            'systems_affected': 'Azure AI Foundry'},
 'investigation_status': 'Resolved',
 'post_incident_analysis': {'corrective_actions': 'Backend patch applied by '
                                                  'Microsoft',
                            'root_causes': 'Missing authentication check '
                                           '(CWE-306) in a critical backend '
                                           'function'},
 'references': [{'source': 'Microsoft Security Response Center'},
                {'source': 'Researcher Rémy Marot'}],
 'response': {'containment_measures': 'Backend fix by Microsoft (no customer '
                                      'action required)',
              'remediation_measures': 'Patch applied to resolve the missing '
                                      'authentication check'},
 'title': 'Critical Azure AI Foundry Vulnerability Patched by Microsoft',
 'type': 'Privilege Escalation',
 'vulnerability_exploited': 'CVE-2026-85889 (Missing Authentication Check - '
                            'CWE-306)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.