CuraSec

Act active

Microsoft Patches CVSS 10.0 Privilege Escalation in Azure AI Foundry

2026-09-18 14:58 UTC · The Hacker News · read the source ↗ #azure#privilege-escalation#cloud-security
  • Engineer — Plan: No customer-side patch action is needed — Microsoft fixed this server-side — but a public PoC existed before the fix, so audit Azure AI Foundry activity and IAM logs for unauthorized privilege escalations that may have occurred during the exposure window.
  • SOC/IR — Act: A public PoC on GitHub combined with a CVSS 10.0 network-accessible privilege escalation means exploitation attempts are plausible; hunt for anomalous privilege escalation events in Azure AI Foundry audit logs and Azure Entra activity logs predating the patch.
  • Leader — Plan: Confirm whether Azure AI Foundry is in use and have the team verify no exploitation occurred during the pre-patch window; the CVSS 10.0 score and public PoC will likely generate customer or board inquiries, so prepare a brief noting Microsoft resolved it server-side with no customer action required.
  • Signals: CVE-2026-85889 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.