Skip to content

Security1 publisher2 min readPublished

Microsoft rates a missing authentication check in Azure AI Foundry at CVSS 10.0

CVE-2026-85889 let an unauthorized attacker elevate privileges over the network in the platform enterprises use to run generative AI agents. Microsoft says the fix is already live and there is nothing for customers to install.

The Watch · Security desk

Illustration accompanying Microsoft rates a missing authentication check in Azure AI Foundry at CVSS 10.0

What happened

  • The company says the cloud flaws are already fully mitigated and require no customer action, credits researcher Rémy Marot with the report, and states there is no evidence of exploitation.
  • Three other critical cloud flaws patched in recent days all require an attacker who is already authorized: Microsoft 365 Copilot at CVSS 9.9, Azure Database for PostgreSQL at 9.9 and Cosmos DB at 9.6.
  • An out-of-band cumulative update, KB5129194 for Windows 11 version 26H1, fixes a User-Mode Power Service access control flaw rated 7.8 and a Secure Kernel Mode double free rated 8.2.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint A controls owner has no build number to compare and no remediation date of their own for CVE-2026-85889, so the only evidence of fix is the vendor advisory.
  • decision Triage this cycle sorts on exploitation, not score: the 10.0 costs zero engineering hours while the exploited ALPC chain costs a rollout across every Windows endpoint.
  • exposure Tenants running agents on Foundry cannot bound their own exposure period, because the reachability window opened and closed inside Microsoft's operations.
  • precedent Unauthenticated privilege escalation now lands at maximum severity in a hosted AI control plane, which puts Foundry advisories in the same triage queue as any internet-facing management product.

Three of the four critical cloud flaws Microsoft fixed in recent days need an attacker who already holds credentials [18]. CVE-2026-85889 needs network reach. "Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network," Microsoft said in a Thursday advisory [2]. The Microsoft 365 Copilot command injection scored 9.9, the Azure Database for PostgreSQL authorization bug 9.9, and the Cosmos DB neutralization bug 9.6 [8][9][10]. The 0.1 of a point between the Foundry flaw and those two 9.9s is the authentication check [19].

Azure AI Foundry, also called Microsoft Foundry, is where enterprises build, deploy and manage generative AI applications and agents [5]. Microsoft credited Rémy Marot with finding and reporting the flaw, and said there is no evidence it has been exploited in the wild [6][7]. The company did not say how long the function was reachable without authentication [20].

For a defender, the 10.0 generates no work at all, because Microsoft says the cloud flaws are fully mitigated and require no user action [11]. The items in this batch that cost hours run on Windows. KB5129194, the out-of-band cumulative update for Windows 11 version 26H1 at build 28000.2956, covers x64 and arm64 systems [14]. It fixes CVE-2026-62721, an access control granularity flaw in the User-Mode Power Service that takes a local authorized attacker to SYSTEM, and CVE-2026-85921, a double free in Secure Kernel Mode that takes one to VTL1 [12][13].

Days earlier Microsoft shipped fixes for 974 vulnerabilities, a record across its portfolio [15]. Two of those are under active exploitation, in Windows Advanced Local Procedure Call and the Windows Update Stack [16]. Proofpoint and Volexity report that the ALPC flaw has been chained with two Google Chrome bugs into an exploit kit called BlueMoon, weaponized by multiple espionage-aligned threat actors to deliver payloads [17].

A missing authentication check on a critical function, reachable by an unauthenticated caller over a network, is a legacy infrastructure failure. Microsoft scored one at 10.0 in the platform its customers are standardizing their agents on, and closed it before telling them [1][5][11].

What to watch

  • Whether Microsoft revises the CVE-2026-85889 advisory with an exposure window or a change in exploitation status.
  • Whether Rémy Marot publishes technical detail on the Foundry function that lacked the authentication check.
  • Whether BlueMoon operators extend past the ALPC plus two-Chrome-bug chain that Proofpoint and Volexity documented.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories