Tools AI Risk Radar ai-incident-0087
Incident record
Azure AI Foundry carried a CVSS 10 missing-authentication flaw, mitigated in the service before customers heard of it
- Severity
- Critical
- Status
- Patched
- Type
- Infra Vuln
- Target
- Microsoft Azure AI Foundry (cloud service)
- Actor
- researcher
- CVE
- CVE-2026-85889
What happened
Missing authentication on a critical function let an unauthorised network attacker elevate privileges, scored CVSS 3.1 10.0. Microsoft states the flaw is fully mitigated server-side with no customer action required and records no exploitation.
Released 17 September in the MSRC update guide as a cloud-service advisory: the class of disclosure where the vulnerability is already closed platform-wide before publication, issued for transparency rather than patching.
Sources
- MSRC advisory CVE-2026-85889msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85889
- NVD record CVE-2026-85889nvd.nist.gov/vuln/detail/CVE-2026-85889
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026