Microsoft Azure AI Foundry CVSS 10.0 Authentication Bypass CVE-2026-85889 and Windows Zero-Day Exploitation
During Microsoft's September 2026 Patch Tuesday, a critical CVSS 10.0 authentication bypass (CVE-2026-85889) was disclosed in the Azure AI Foundry internal management API. This vulnerability allowed unauthenticated network attackers to invoke privileged functions, enabling immediate administrator role escalation. A subsequent chain of five vulnerabilities (CVE-2026-85890 through CVE-2026-85894) facilitated cross-tenant access, session hijacking, and arbitrary code execution within the Foundry sandbox. Concurrently, two Windows zero-day vulnerabilities in win32k.sys (CWE-416) and spoolsv.exe (CWE-120) were observed being actively exploited in the wild for approximately 72 hours before out-of-band patches were released. While the Azure vulnerability was mitigated server-side, immediate client-side patching is required for all Windows systems to prevent kernel-mode exploitation.
- Vulnerability Mechanics: Azure AI Foundry Cluster
- CVE-2026-85889: Missing authentication (CWE-306) on the
/admin/internal/functionendpoint enables unauthenticated acquisition of admin tokens. - Escalation Chain: Includes CVE-2026-85890 (improper authorization), CVE-2026-85891 (service account token leakage), and CVE-2026-85892 (insufficient token validation enabling cross-tenant access).
-
Sandbox Escape: CVE-2026-85894 (CWE-434) leverages an unrestricted file upload in the diagnostic webhook to achieve arbitrary code execution.
-
Windows Zero-Day Exploitation
- Kernel-Mode Execution: CVE-2026-XXXXX utilizes a use-after-free (CWE-416) in
win32k.sysvia malicious font parsing to achieve RCE. - Local Privilege Escalation: CVE-2026-YYYYY involves a buffer overflow (CWE-120) in
spoolsv.exetriggered by crafted print jobs. -
Active Exploitation: Threat telemetry from CrowdStrike and Mandiant confirmed both zero-days were active for ~72 hours prior to the September 12, 2026, out-of-band patch release.
-
Impact and Blast Radius
- Cloud Infrastructure: Potential for full administrative control over Azure AI Foundry and lateral movement into connected M365 environments.
- Data Exfiltration: High risk of theft regarding proprietary AI models, sensitive training datasets, and service account credentials.
-
Host Integrity: Windows exploits allow for full system compromise and kernel-level persistence on Windows 10/11 and Server 2022.
-
Mitigation and Defensive Guidance
- Azure Remediation: Mitigation was applied server-side on September 10, 2026; administrators should monitor API logs for anomalous unauthenticated POST requests.
- Windows Patching: Immediate deployment of KB502XXXX and KB502YYYY is mandatory to remediate active zero-day threats.
- Security Hardening: Enforce MFA for all Foundry admin roles, implement least-privilege for service accounts, and restrict access to the print spooler.
Related posts
- The Hacker News — Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
- forkast.news — Azure AI Foundry Had a CVSS 10.0 Authentication Bypass – Microsoft Fixed It Silently and Told Nobody
- Onesourceit
- Shattered
- Xhack
- Neoteo
- Youtube