Microsoft has released fixes that are applied automatically; no customer action is required. Organizations should verify that their Azure AI Foundry instances are updated and review Microsoft's security advisories for any additional guidance. It is also recommended to monitor for unusual activity and enforce least-privilege access controls.
Quick answers
What is CVE-2026-85889?
Microsoft has released fixes that are applied automatically; no customer action is required. Organizations should verify that their Azure AI Foundry instances are updated and review Microsoft's security advisories for any additional guidance. It is also recommended to monitor for unusual activity and enforce least-privilege access controls.
How severe is CVE-2026-85889?
critical, CVSS 10
Is CVE-2026-85889 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-85889 be mitigated?
Microsoft has released fixes that are applied automatically; no customer action is required. Organizations should verify that their Azure AI Foundry instances are updated and review Microsoft's security advisories for any additional guidance. It is also recommended to monitor for unusual activity and enforce least-privilege access controls.
CVSS
10
Vendor
Microsoft
Published
Sep 30, 2026 · 08:43
Patch
Unknown / not confirmed
Affected products
Azure AI Foundry
Mitigation
Microsoft has released fixes that are applied automatically; no customer action is required. Organizations should verify that their Azure AI Foundry instances are updated and review Microsoft's security advisories for any additional guidance. It is also recommended to monitor for unusual activity and enforce least-privilege access controls.
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could allow unauthorized privilege escalation over a network. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. Microsoft states that no customer action is required as updates are applied automatically.