Microsoft Fixes Critical Azure AI Foundry Flaw Without Customer Action
Microsoft fixed CVE-2026-85889 on the Azure AI Foundry service side. The CVSS 10.0 flaw could have allowed an unauthorized attacker to escalate privileges over a network.

Azure AI Foundry was affected by the critical vulnerability CVE-2026-85889, which Microsoft fixed directly on the cloud service side. The vulnerability received the maximum CVSS 3.1 score of 10.0 and, according to Microsoft’s record, could have allowed an unauthorized attacker to escalate privileges over a network.
Microsoft states that customers do not need to take any action or install an update. The fix was deployed to the service. Microsoft credits security researcher Rémy Marot with reporting the flaw.
Critical Azure AI Foundry Flaw Has a CVSS Score of 10.0
The CVE-2026-85889 record describes missing authentication for a critical function, classified as CWE-306. According to the CVSS vector, the attacker did not need to be authenticated, and exploitation required no user interaction.
A successful attack could affect the confidentiality, integrity, and availability of resources managed through Azure AI Foundry. It is the highest-rated remotely exploitable flaw in the platform for enterprise AI applications.
Microsoft published information about the vulnerability on September 17, 2026. As of September 18, it had not been marked as actively exploited in publicly available listings.
The Fix Was Applied in the Cloud
Because Microsoft remediated the issue on the service side, Microsoft says customers do not need to install an update or take any other action.
Independent public technical details that would precisely determine the flaw’s impact on individual tenants or projects are not yet available. No exploitation in the wild has been confirmed, although undisclosed attack attempts cannot be ruled out.
Despite the fix, organizations using the service may review sensitive activity and permissions in their Azure AI Foundry environments.
What to Watch Next
- a more detailed analysis of the flaw’s scope or indicators of compromise from Microsoft,
- any change in its active-exploitation status,
- a public proof of concept or independent reports of attack attempts,
- any additional Microsoft recommendations on auditing logs and access credentials.
Sources
- Microsoft Security Response Center – Microsoft’s primary record is the source for the CVE identifier, CVSS score, description of the missing authentication, researcher credit, and service remediation status.
- NIST National Vulnerability Database – The CVE record lists the publication date of September 17, 2026, the Azure AI Foundry product, CWE-306, and a CVSS vector with a value of 10.0.
- SecurityWeek – Independently confirms that the cloud fixes were applied on the service side, with no customer action required, and were not marked as exploited.
Verified and updated: 09/18/2026 15:30



