Microsoft patches maximum-severity CVSS 10.0 Azure AI Foundry flaw

Microsoft patched 18 vulnerabilities across its Azure cloud and AI-branded products, with privilege-escalation flaws accounting for the majority. The headline issue is a maximum-severity CVSS 10.0 flaw in Azure AI Foundry (CVE-2026-85889) that enabled unauthenticated privilege escalation — one of the most severe classes of cloud vulnerability possible. Two additional CVSS 10.0 issues affected Azure Billing and Microsoft Fabric.
All fixes were deployed server-side, meaning customers need take no action to be protected. Security researchers nonetheless emphasized that organizations should monitor privileged identities and audit access, since a CVSS 10.0 privilege-escalation bug in an AI-development platform is exactly the kind of weakness that could have enabled lateral movement had it been exploited before patching. The disclosure lands amid an intense week for AI-infrastructure security following the Hugging Face intrusion reports.
The context is Microsoft's soaring AI-cloud spend and revenue. Azure surpassed $100 billion in annual revenue for the first time, growing 43% year-over-year, even as market anxiety builds over whether cloud growth is topping out and whether record capital expenditure (a reported $88 billion in FY2025 on chips and data centers) will pay off. The juxtaposition is pointed: Microsoft is monetizing AI at unprecedented scale while simultaneously shipping maximum-severity patches for the very AI platforms enterprises are being urged to build on. For security teams, the takeaway is that AI-branded cloud services carry the same — arguably higher — attack surface as traditional infrastructure, and vendor server-side patching is a mercy but not a substitute for identity monitoring.