Azure AI Foundry missing auth CVE-2026-85889 (CVSS 10.0) + SSRF CVE-2026-85917 (7.5); cloud-mitigated
Microsoft Security Update Guide (September 2026 release; MSRC releaseDate 17 September 2026 PDT) published two exclusively-hosted Azure AI Foundry elevation-of-privilege CVEs for transparency. CVE-2026-85889 (Critical, Microsoft CVSS 3.1 base 10.0, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; CWE-306): missing authentication for a critical function allows an unauthenticated network attacker to elevate privileges. CVE-2026-85917 (Critical impact class / High base 7.5, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N; CWE-918): SSRF allowing unauthenticated privilege elevation. Microsoft states both are already fully mitigated in the hosted service — no customer patch action; CVEs are for cloud transparency (aka.ms/MSRC-Cloud-CVEs). MSRC: publicly disclosed No; exploited No. NVD received records 17 September 2026. Primary: MSRC CVE-2026-85889; companion: MSRC CVE-2026-85917; NVD indexes both.
- Product
- Microsoft Azure AI Foundry (exclusively hosted cloud service)
- Versions
- Hosted service (exclusively-hosted-service tag); not an on-prem build train — Microsoft states already fully mitigated
- CVSS
- (CVE-2026-85889); 7.5 (CVE-2026-85917) — CVSS 3.1 Microsoft
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (85889); CVSS:3.1 - Exploited in Australia?
- unknown
- Patch to
- No customer action — Microsoft states fully mitigated in the hosted Azure AI Foundry service (transparency CVE)
Primary: MSRC — CVE-2026-85889 Azure AI Foundry missing authentication (17 Sep 2026) · Vendor: Microsoft Security Update Guide — Azure AI Foundry · CVE: CVE-2026-85889, CVE-2026-85917 · MSRC — CVE-2026-85917 Azure AI Foundry SSRF (same release); also NVD
