Thehackernews Microsoft Addresses CVSS 10 Vulnerability in Azure AI Foundry
Article Content
- •CVE-2026-85889 in Azure AI Foundry has a CVSS score of 10.0, allowing unauthorized privilege escalation.
- •No customer action is needed for Azure AI Foundry, but Windows vulnerabilities require manual updates.
- •The vulnerability was discovered by researcher Rémy Marot, with no known exploitation reported.
On September 17, 2026, Microsoft patched a critical vulnerability in Azure AI Foundry, identified as CVE-2026-85889, which had a CVSS score of 10.0. This flaw allowed unauthorized privilege escalation due to missing authentication for critical functions. The vulnerability affects Azure AI Foundry, a platform for developing generative AI applications, but there is no evidence of exploitation in the wild. Microsoft also addressed additional vulnerabilities in other products, including two in Windows that require manual updates. Security researcher Rémy Marot discovered the flaw, and Microsoft has advised that no customer action is needed for the Azure AI Foundry patch. However, administrators must manually install the cumulative update KB5129194 for the two Windows vulnerabilities. Overall, Microsoft patched 18 vulnerabilities across various products in this update cycle.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (8)
Following this threat?
Track Azure and CVE-2026-62721 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Microsoft Windows 11 Update Causes Widespread Audio Failures Microsoft's September 2026 Patch Tuesday update introduced critical audio issues affecting USB Audio Class 1.0 devices on Windows 11 versions 24H2 and 25H2. Users reported that audio devices either failed to start or produced no sound, with Device Manager showing error code 10. The update, KB5124008, was part of a…
Critical Elevation of Privilege Vulnerabilities in Windows 11 and 10 Microsoft has released out-of-band security updates for Windows 11 (versions 24H2, 25H2, and 26H1) and Windows 10 (version 1809) to address critical elevation of privilege vulnerabilities. The updates include protections for CVE-2026-62721, a Windows User-Mode Power Service vulnerability published on August 11, 2026…