← All briefs
Brief·3 sources18 Sept 2026

CVE-2026-85889 Patched In Azure AI Foundry Privilege Escalation Disclosure

vulnerability-disclosurecloud-securityprivilege-escalationpatch-managementai-threats

Summary

CVE-2026-85889 is a CVSS 10.0 maximum-severity elevation of privilege vulnerability in Microsoft Azure AI Foundry, disclosed and patched by Microsoft on 17 September 2026. The flaw stems from missing authentication for a critical function, permitting an unauthenticated remote attacker to elevate privileges over a network without any user interaction.

Microsoft has confirmed the fix was applied at the service level. Because Azure AI Foundry is a managed cloud service, no customer action is required. There is no evidence of exploitation in the wild at the time of disclosure, and no public proof-of-concept exploit has been observed.

The CVSS 10.0 score reflects the combination of network-accessible attack surface, zero authentication requirement, and the severity of the privilege escalation outcome. Organisations consuming Azure AI Foundry workloads should verify service-side patch status through the Microsoft Security Response Center advisory and monitor for any anomalous activity in their AI Foundry environments as a precautionary measure.

Timeline

  1. 18 September 2026
    The Hacker News Reports Microsoft Patch for Maximum-Severity Azure AI Foundry Flaw
    Wider security press coverage confirmed the CVSS 10.0 rating and Microsoft's statement that no customer action is required, increasing industry awareness of the vulnerability.
  2. 17 September 2026
    Microsoft MSRC Publishes CVE-2026-85889 Advisory
    Microsoft released the official advisory for CVE-2026-85889, disclosing a CVSS 10.0 missing-authentication elevation of privilege flaw in Azure AI Foundry. The service-level fix was applied simultaneously, with no customer action required.
  3. 17 September 2026
    VulDB Catalogues CVE-2026-85889 With No Known Exploit
    VulDB published an entry confirming the vulnerability as remotely exploitable with no available exploit code at time of publication, and noted the managed-service delivery model limits customer-side countermeasures.

Want the full picture?

Each brief contains detailed narrative, impact assessments, technical analysis, IOCs and response recommendations, all available inside the Deltabridge platform.

CVE-2026-85889 Patched In Azure AI Foundry Privilege Escalation Disclosure | Deltabridge