importantSYS.SOURCE: The Hacker News• 2026-09-18T18:17:04+05:30
Microsoft Addresses Critical CVSS 10.0 Vulnerability in Azure AI Foundry for Privilege Escalation
Microsoft has resolved a critical CVSS 10.0 vulnerability (CVE-2026-85889) in Azure AI Foundry, which could allow unauthorized privilege escalation. The flaw was addressed without requiring customer intervention, as part of broader security updates across Microsoft's ecosystem.
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required.
The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0.
"Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,"
*** END OF TRANSMISSION ***