Microsoft closed a security vulnerability with the highest possible rating of ten out of ten in its AI platform Azure AI Foundry on September 17, 2026. A lack of authentication made a central function reachable for any attacker on the network – with no credentials or user interaction required.
Unprotected function opens path to escalated privileges
The flaw is tracked as CVE-2026-85889 and classified as missing authentication for a critical function, known in technical jargon as CWE-306. An attacker with no valid credentials could reportedly reach a specific backend function of Azure AI Foundry directly and use it to escalate access rights within the system. The check meant to verify who is allowed to perform such an action simply did not apply at that point.
As The Hacker News reports, the attack was possible over the network with little technical effort and required neither prior knowledge nor any action from affected users. That combination is what justifies the CVSS maximum score of ten points. Azure AI Foundry is Microsoft’s central platform for building, testing, and running generative AI applications and autonomous agents – aimed at business customers, not private users.
Researcher reports the flaw, Microsoft fixes it behind the scenes
Security researcher Rémy Marot discovered the flaw and reported it through Microsoft’s coordinated vulnerability disclosure program. According to the vendor’s security advisory dated September 17, 2026, the vulnerability had already been fully resolved by that point. Because Azure AI Foundry runs as a cloud service, the fix was applied server-side.
Customers therefore did not have to install any update of their own. No actual exploitation is known, nor any publicly available attack code – that assessment has not been independently verified. Microsoft did not disclose how much time passed between Marot’s report and the fix.
Critical flaws are piling up across AI company platforms
Azure AI Foundry is not the only enterprise AI platform in 2026 with a flaw at the top of the CVSS scale. Just in August, ServiceNow closed four critical vulnerabilities in its AI platform, three of which also carried the maximum rating of ten; the company likewise reported no known attacks.
That same month, security firm Rapid7 chained two vulnerabilities in Microsoft SharePoint into an attack path granting full server access, aided by an AI agent during the search. What these cases share is that the affected systems specifically target companies weaving generative AI into existing workflows – creating larger attack surfaces with far-reaching access rights.
It remains an open question how many similar authentication gaps still lurk undiscovered in the many new AI services rolled out by major cloud providers. For companies running Foundry agents in production, the incident is above all a reminder to demand independent permission audits of any deployed service before rollout – the cloud provider alone is not enough as a control instance.


