decrypted · 19 september 2026 · vulnerabilities and patching · uk policy and law · digital sovereignty

Microsoft fixed a maximum-severity Azure AI flaw and told customers to do nothing

Microsoft fixed a maximum-severity flaw in Azure AI Foundry this week, and its advice to customers is to do nothing. That is reassuring and slightly unsettling in equal measure, because "nothing to do" also means nothing to check.

A door nobody thought to lock

Microsoft's advisory for CVE-2026-85889 describes "missing authentication for critical function in Azure AI Foundry" that "allows an unauthorized attacker to elevate privileges over a network". The Hacker News reports a CVSS score of 10.0, the maximum. Microsoft credits the researcher Rémy Marot with finding it, and both The Hacker News and SecurityWeek report no evidence of exploitation. Microsoft has fixed it on its own side of the wall, so customers need not patch or reconfigure anything.

The analogy: picture an office where every front door needs a keycard, but a service hatch round the back opens into the staff corridor and nobody ever asked who was crawling through. "Missing authentication" means the function could be reached and never asked who was calling. Nobody had to pick a lock, because there was no lock. Microsoft has not said which function it was, so we do not know how much a caller could have reached.

Fixed for you, but not by you

The same day, SecurityWeek reports, Microsoft fixed 18 vulnerabilities across Azure and Copilot products, mostly privilege escalation bugs, none flagged as exploited, all remedied server-side. The Hacker News lists others near the top of the scale:

This is the good version of cloud security. The vendor found and fixed problems before customers had to scramble. But look at it from the director's chair: you learned about a perfect-score flaw in a platform holding your AI workloads after it was closed, and your only evidence that nobody walked through it is Microsoft's statement that it found none. I am not suggesting that statement is wrong. I am pointing out that you cannot test it.

The Secure by Design reading

The design decision that would have prevented this is dull: every function authenticates its caller, every time, rather than trusting that the front door did the job. AI platforms are being assembled at speed, and authentication is not a feature to bolt on in the next sprint.

For UK organisations, my opinion, not advice:

Also this week

Age checks, EU and UK. On 17 September the European Commission proposed the EU KIDS Act: no social media under 13, parent-managed "mini accounts" for 13 to under 15, and an EU age verification app that does not retain identity documents or biometric data. Parliament and Council must still agree the text. The UK is on a different track: the government has said it will ban under-16s, with an Ofcom assessment of age assurance due by the end of October 2026 and protections expected in spring 2027. Two ages, two regimes, one hard problem: every age check is a data store, and someone has to design it not to become a breach.

Gyazo breach. Helpfeel, which runs the screenshot service Gyazo, says an attacker exploited a vulnerability in its image upload server on 11 September, reaching about 23.62 million user records and about 490 million image metadata records. The exposed data includes password hashes, and image metadata includes upload IP addresses, EXIF location data and text extracted from screenshots. The company says it cannot rule out that some private images were viewed. Its notice references Japan's regulator and says nothing about UK users, so I cannot say whether UK data is involved. Worth asking whether staff use screenshot tools that quietly upload company material.

Four Linux root exploits. Researcher Asim Manizada published working exploits on 18 September for four local privilege escalation bugs: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121 and CVE-2026-74469. Fixes already exist in kernel releases including 6.1.188 and 6.12.109, and no active exploitation has been reported. The exploits are tuned to specific kernel builds. "Local" means an attacker needs a foothold first, but shared hosts and container platforms are where a foothold is cheapest. Manizada used an AI-assisted process to find them, which is the trend to watch: defenders' patch windows are shrinking.

Sources

If you would like a second pair of eyes on your cloud and AI supplier risks, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.