Microsoft Fixes Severe Azure AI Flaw Without User Action

Microsoft has resolved a critical security gap in its Azure AI Foundry platform, closing a door that allowed unauthorized network attackers to seize higher system privileges.
The vulnerability, identified as CVE-2026-85889, carries the highest possible severity rating of 10.0 on the Common Vulnerability Scoring System. This score indicates that an attacker could exploit the flaw remotely without needing prior authentication to the system. The issue stemmed from a missing authentication check on a critical function, effectively leaving a key management area of the platform open to unauthorized access.
According to reports from The Hacker News, Microsoft has already deployed the necessary fixes to its cloud infrastructure. Consequently, enterprise customers do not need to perform any manual updates or configuration changes to secure their environments. The company stated that the vulnerability has been fully mitigated on the server side, ensuring that the exposure is closed for all users of the Azure AI Foundry service.
Researcher identified the critical gap
The flaw was discovered by security researcher Rémy Marot, who reported the issue to Microsoft prior to public disclosure. There is currently no evidence that this specific vulnerability has been exploited in the wild by malicious actors. However, the existence of a maximum-severity bug in a platform designed for building and managing generative AI applications raises significant concerns about the robustness of automated AI deployment pipelines.
Other critical flaws patched recently
The Azure AI Foundry fix is part of a broader wave of security updates released by Microsoft. Several other high-severity vulnerabilities were also addressed, including a command injection flaw in Microsoft 365 Copilot and authorization issues in Azure Database for PostgreSQL. These additional bugs carried scores ranging from 9.6 to 9.9, allowing attackers with some level of authorized access to escalate their privileges over the network.
In addition to cloud services, Microsoft released out-of-band updates for Windows 11 version 26H1. These updates address two distinct local privilege escalation vulnerabilities in the Windows User-Mode Power Service and the Secure Kernel Mode. While these local flaws require an attacker to already have a foothold on the system, they pose a significant risk to internal security if exploited.
Active exploitation of other bugs
The recent patch cycle follows a record-breaking release of fixes for over 970 vulnerabilities across Microsoft’s software portfolio. Unlike the Azure AI Foundry issue, some of these other defects are already under active attack. Reports indicate that a vulnerability in the Windows Advanced Local Procedure Call component is being chained with browser flaws to create an exploit kit known as BlueMoon.
This exploit kit has been weaponized by espionage-aligned threat groups to deliver malicious payloads. The contrast highlights a key trade-off in cloud security: while cloud providers can silently patch server-side issues without user intervention, the rapid pace of exploitation for client-side vulnerabilities requires immediate action from end-users to remain protected.






