Skip to content
Microsoft Addresses CVSS 10 Vulnerability in Azure AI Foundry

Microsoft Addresses CVSS 10 Vulnerability in Azure AI Foundry

First seen 18 Sep 2026, 20:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 19, 2026 at 19:58 UTC

On September 17, 2026, Microsoft patched a critical vulnerability in Azure AI Foundry, identified as CVE-2026-85889, which had a CVSS score of 10.0. This flaw allowed unauthorized privilege escalation due to missing authentication for critical functions. The vulnerability affects Azure AI Foundry, a platform for developing generative AI applications, but there is no evidence of exploitation in the wild. Microsoft also addressed additional vulnerabilities in other products, including two in Windows that require manual updates. Security researcher Rémy Marot discovered the flaw, and Microsoft has advised that no customer action is needed for the Azure AI Foundry patch. However, administrators must manually install the cumulative update KB5129194 for the two Windows vulnerabilities. Overall, Microsoft patched 18 vulnerabilities across various products in this update cycle.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-08-11
CVE-2026-62721 published
An insufficient access control vulnerability in Windows was disclosed, requiring manual updates.
DiarioBitcoin
2026-09-14
CVE-2026-85921 published
A vulnerability in Windows requiring manual update KB5129194 was disclosed.
DiarioBitcoin
2026-09-17
CVE-2026-85889 patched
Microsoft released a patch for a critical vulnerability in Azure AI Foundry allowing unauthorized privilege escalation.
DiarioBitcoin
2026-09-17
CVE-2026-85885 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (8)

Following this threat?

Track Azure and CVE-2026-62721 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed