Microsoft Fixes Maximum-Severity Flaw in Azure AI Foundry
Microsoft has released a fix for a maximum-severity security flaw in Azure AI Foundry, its platform for building and managing generative AI applications and agents. The vulnerability, tracked as CVE-2026-85889, scored a full 10.0 on the CVSS scale and stemmed from a missing authentication check on a critical function, which could have allowed an unauthorized attacker to elevate privileges over a network.
Microsoft credited researcher Rémy Marot with discovering and reporting the issue, and said there is no evidence it was exploited before the patch. Because Azure AI Foundry is a cloud-based service, Microsoft has already applied the fix on its end, meaning customers do not need to take any action themselves.
The fix arrives alongside a series of other critical patches Microsoft has issued recently, including out-of-band updates for Windows 11 version 26H1 addressing two additional vulnerabilities. This follows a record-breaking patch batch of 974 vulnerabilities released the previous week, two of which, affecting Windows ALPC and the Windows Update Stack, are already being actively exploited in the wild as part of an exploit kit called BlueMoon used by espionage-linked threat actors.