A missing authentication check gave Azure AI Foundry a perfect 10

Microsoft has mitigated a CVSS 10.0 authentication gap in Azure AI Foundry and says customers need take no action.

CSBadmin
2 Min Read

Microsoft has closed a maximum-severity hole in Azure AI Foundry, the hosted service it sells for assembling and running generative AI applications and agents. CVE-2026-85889 carries a CVSS score of 10.0.

Microsoft’s Thursday advisory files it as missing authentication for a critical function: it “allows an unauthorized attacker to elevate privileges over a network.” Rémy Marot is credited with the report, and nothing suggests it has been used in the wild.

The quiet part of a cloud fix

No customer action is required, Microsoft says, because the work happened on its own infrastructure and the exposure is already mitigated. That is the usual shape of a cloud CVE, and why a perfect ten can come and go without any patch window opening. The hole was still there, and nothing in that says what a customer has built on top of the platform.

What Foundry holds is what matters: the endpoints its models answer on, the data sources wired in, and the agent identities it hands out. An authentication check missing from that control plane is a route to everything behind it.

Redmond patched more than this. Command injection in Microsoft 365 Copilot rates 9.9 as CVE-2026-85885, improper authorization in Azure Database for PostgreSQL is 9.9 as CVE-2026-85878, and improper neutralization in Azure Cosmos DB is 9.6 as CVE-2026-87701. An out-of-band Windows 11 26H1 update, KB5129194, covers two more, one disclosed last month: an access-control granularity problem in the Windows User-Mode Power Service (CVE-2026-62721, 7.8) and a double free in Windows Secure Kernel Mode (CVE-2026-85921, 8.2).

It lands days after a record 974-fix release, where the Windows ALPC and Update Stack bugs were already exploited. Proofpoint and Volexity report that ALPC was chained with two Chrome flaws into an exploit kit called BlueMoon, used by several espionage-aligned groups.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.