{"version":1,"type":"story","url":"https://digestai.news/story/microsoft-patches-cvss-10-0-azure-ai-foundry-flaw-cve-2026-85889","json":"https://digestai.news/story/microsoft-patches-cvss-10-0-azure-ai-foundry-flaw-cve-2026-85889.json","markdown":"https://digestai.news/story/microsoft-patches-cvss-10-0-azure-ai-foundry-flaw-cve-2026-85889.md","slug":"microsoft-patches-cvss-10-0-azure-ai-foundry-flaw-cve-2026-85889","headline":"Microsoft patches CVSS 10.0 Azure AI Foundry flaw (CVE-2026-85889)","summary":"Microsoft issued an out‑of‑band update that fixes a CVSS 10.0 vulnerability in Azure AI Foundry, also known as Microsoft Foundry. The flaw (CVE‑2026‑85889) allowed an unauthenticated attacker to elevate privileges over a network, but Microsoft said there is no evidence of exploitation and no customer action is required. Security researcher Rémy Marot was credited for discovering the issue.\n\nThe advisory also listed several other critical patches released at the same time, including CVE‑2026‑85885 and CVE‑2026‑85878 (both CVSS 9.9) affecting Microsoft 365 Copilot and Azure Database for PostgreSQL, and CVE‑2026‑87701 (CVSS 9.6) in Azure Cosmos DB. Earlier in September, Microsoft patched a record 974 vulnerabilities across its portfolio, with two Windows bugs actively exploited in the wild and linked to the BlueMoon exploit kit used by espionage‑aligned actors.\n\nThese updates demonstrate Microsoft’s rapid response to high‑severity flaws in its cloud and AI services, aiming to protect enterprise customers from privilege‑escalation attacks.","keyPoints":["Azure AI Foundry CVE‑2026‑85889 scored 10.0 and allowed unauthenticated privilege escalation","Microsoft credited researcher Rémy Marot and said no evidence of wild exploitation","Microsoft patched a record 974 vulnerabilities in September, including two actively exploited Windows bugs"],"whyItMatters":"A maximum‑severity flaw in a core AI platform could let attackers compromise enterprise workloads; the patch removes that risk and shows Microsoft’s security responsiveness.","category":{"slug":"enterprise","name":"Enterprise & Industry","url":"https://digestai.news/category/enterprise"},"entities":{"companies":["Microsoft"],"models":[],"people":["Rémy Marot"]},"firstPublishedAt":"2026-09-18T05:47:00Z","updatedAt":"2026-09-18T05:47:00Z","sourceCount":1,"hasPrimarySource":false,"sources":[{"outlet":"thehackernews.com","title":"Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation","url":"https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html","publishedAt":"2026-09-18T05:47:00Z","type":"press","primary":false,"lead":true}],"sourceNotes":null,"discussions":[],"thread":null,"cite":{"text":"Digest AI, \"Microsoft patches CVSS 10.0 Azure AI Foundry flaw (CVE-2026-85889)\", 18 September 2026, https://digestai.news/story/microsoft-patches-cvss-10-0-azure-ai-foundry-flaw-cve-2026-85889","publisher":"Digest AI","title":"Microsoft patches CVSS 10.0 Azure AI Foundry flaw (CVE-2026-85889)","datePublished":"2026-09-18T05:47:00Z","url":"https://digestai.news/story/microsoft-patches-cvss-10-0-azure-ai-foundry-flaw-cve-2026-85889"},"generatedBy":"Written by Digest AI's editorial model from the linked sources; the sources are the record.","license":"Headlines, digests and key points are written by Digest AI and may be quoted with a link to the story page. Linked articles belong to their publishers. Terms: https://digestai.news/terms#reuse"}