Microsoft Patches Maximum-Severity Azure AI Foundry Bug
A CVSS 10.0 privilege escalation vulnerability in Azure AI Foundry was patched as part of a broader Microsoft security update.
Microsoft has released fixes for a critical security vulnerability in Azure AI Foundry, tracked as CVE-2026-85889, with a CVSS score of 10.0. The flaw stems from missing authentication and could allow unauthorized privilege escalation.
The patch is part of a larger update. SecurityWeek reports that Microsoft fixed 18 vulnerabilities across its AI and cloud products, with privilege escalation flaws accounting for the majority. Both sources agree on the importance of the update, though The Hacker News focuses on the single most severe issue.
The Hacker News notes that no customer action is required, while SecurityWeek's summary does not address customer action. This difference aside, the two reports align on the scope of the fixes and the emphasis on privilege escalation.
Sources · 2
More in Security & Privacy
WordPress Click2Shell CSRF Flaw Could Let Attackers Run PHP Code
A newly disclosed cross-site request forgery vulnerability in WordPress Core, with a public proof-of-concept, can let attackers execute PHP on the server.
Film Torrents Carry New Malware, Victims Found in Kenya and Uganda
Cybercriminals are using popular movie torrents to distribute fresh malware, with confirmed infections in East Africa.
CrowdSec Breach: TanStack npm Attack Exposed 170 Private Repos
CrowdSec says an attacker used a former employee's still-active GitHub access to copy 170 private repositories, tracing the intrusion to the TanStack npm attack.
CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
The agency's move signals active attacks and pressures federal agencies to patch quickly.