Security

Microsoft closes critical security flaw in Azure AI Foundry

2 min read

TL;DR Too Long; Didn’t read

Microsoft closed a security vulnerability with a maximum rating of ten out of ten in its AI platform Azure AI Foundry on September 17, 2026. A lack of authentication allowed unauthorized network access to a critical function without any credentials. Security researcher Rémy Marot reported the flaw before it was exploited, according to the company. Customers do not need to take any action, as Microsoft fixed the vulnerability server-side.

An open padlock without a shackle floats above a cloud bearing the Microsoft logo, a drawn hand reaching through it unimpeded toward a circuit symbol. Image generated with GPT Image 2

Key takeaways

  • Azure AI Foundry had a system function reachable over the network without any login at all.
  • The flaw received the highest possible rating on the ten-point CVSS scale.
  • Rémy Marot discovered the vulnerability and reported it through Microsoft's official disclosure process.
  • Microsoft fixed the vulnerability server-side – affected companies had nothing to patch themselves.
  • It is already the second enterprise AI platform with a CVSS maximum rating of ten within a few weeks.

Microsoft closed a security vulnerability with the highest possible rating of ten out of ten in its AI platform Azure AI Foundry on September 17, 2026. A lack of authentication made a central function reachable for any attacker on the network – with no credentials or user interaction required.

Unprotected function opens path to escalated privileges

The flaw is tracked as CVE-2026-85889 and classified as missing authentication for a critical function, known in technical jargon as CWE-306. An attacker with no valid credentials could reportedly reach a specific backend function of Azure AI Foundry directly and use it to escalate access rights within the system. The check meant to verify who is allowed to perform such an action simply did not apply at that point.

As The Hacker News reports, the attack was possible over the network with little technical effort and required neither prior knowledge nor any action from affected users. That combination is what justifies the CVSS maximum score of ten points. Azure AI Foundry is Microsoft’s central platform for building, testing, and running generative AI applications and autonomous agents – aimed at business customers, not private users.

Researcher reports the flaw, Microsoft fixes it behind the scenes

Security researcher Rémy Marot discovered the flaw and reported it through Microsoft’s coordinated vulnerability disclosure program. According to the vendor’s security advisory dated September 17, 2026, the vulnerability had already been fully resolved by that point. Because Azure AI Foundry runs as a cloud service, the fix was applied server-side.

Customers therefore did not have to install any update of their own. No actual exploitation is known, nor any publicly available attack code – that assessment has not been independently verified. Microsoft did not disclose how much time passed between Marot’s report and the fix.

Critical flaws are piling up across AI company platforms

Azure AI Foundry is not the only enterprise AI platform in 2026 with a flaw at the top of the CVSS scale. Just in August, ServiceNow closed four critical vulnerabilities in its AI platform, three of which also carried the maximum rating of ten; the company likewise reported no known attacks.

That same month, security firm Rapid7 chained two vulnerabilities in Microsoft SharePoint into an attack path granting full server access, aided by an AI agent during the search. What these cases share is that the affected systems specifically target companies weaving generative AI into existing workflows – creating larger attack surfaces with far-reaching access rights.

It remains an open question how many similar authentication gaps still lurk undiscovered in the many new AI services rolled out by major cloud providers. For companies running Foundry agents in production, the incident is above all a reminder to demand independent permission audits of any deployed service before rollout – the cloud provider alone is not enough as a control instance.

Frequently asked questions

Do Azure AI Foundry customers need to do anything?

No, Microsoft fully fixed the vulnerability server-side; no update or patch on the customer side is necessary.

Was the security flaw exploited?

Microsoft states there is no evidence of active exploitation or publicly available attack code. This has not been independently confirmed.

What is Azure AI Foundry?

A Microsoft platform through which companies develop, test, and operate generative AI applications and autonomous agents.

Who found the vulnerability?

Security researcher Rémy Marot discovered it and reported it through Microsoft's coordinated disclosure program.

Is this an isolated case among AI platforms?

No: in August 2026, ServiceNow also closed four critical vulnerabilities in its AI platform, three of which also carried the maximum rating of ten.

Sources (2)
  1. Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
  2. Microsoft Security Response Center – CVE-2026-85889

Your AI update for the work week

Once a week, the most important AI news – plus one practical tip to try right away. No spam, unsubscribe anytime.

← Back to the blog