CVE-2026-35435Active Exploitation(microsoft / azure_ai_foundry)

LOWCVSS 10.0 · CRITICAL

Exploitation ongoing with high activity in latest observed window (4 mentions)

Immediate actions

  • Prioritize remediation for microsoft azure_ai_foundry systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • azure_ai_foundry

Threat summary

  • Active exploitation appears in 3 classified signals
  • 9 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-06-10)
  • 9 total mentions across 5 days

Affected systems

Vendors
Products
azure_ai_foundry

1 version affected across 1 product

Deep dive

Activity timeline9 mentions / 5d
01234Mentions · 2026-05-08: 1Mentions · 2026-05-10: 2Mentions · 2026-05-13: 1Mentions · 2026-05-19: 1Mentions · 2026-06-10: 4Active Exploitation · 2026-05-08: 1Active Exploitation · 2026-06-10: 2Technical Details · 2026-05-10: 2Technical Details · 2026-05-13: 1Technical Details · 2026-05-19: 1Technical Details · 2026-06-10: 405-0805-1005-1305-1906-10
Signal classification3 categories
Active Exploitation
333.3%
Disclosure
333.3%
General
333.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-081
Active Exploitation1
2026-05-102
Disclosure2
2026-05-131
General1
2026-05-191
General1
2026-06-104
Active Exploitation2Disclosure1General1
Full discourse9 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-35435 Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-35435

    Post summary

    The post announces a new Azure AI Foundry M365 privilege‑escalation flaw caused by improper access control, with no exploit, patch, or active exploitation details provided.

    00020249
    57.8K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting Microsoft Azure AI Foundry (CVE-2026-35435) https://vuldb.com/vuln/361965/cti

    Post summary

    The CTI team reports widespread exploitation activity targeting Microsoft Azure AI Foundry via CVE-2026-35435, indicating active use of this vulnerability in the wild.

    0101074
    2.1K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    TL;DR Microsoft has disclosed CVE-2026-35435, a critical privilege escalation vulnerability in Azure AI Foundry that allows attackers to bypass access controls governing published AI agents. No patch exists. The zero-day is already being exploited in the wild, giving…

    Post summary

    The text announces CVE-2026-35435, a critical privilege escalation flaw in Azure AI Foundry, notes that no patch is available, and confirms the vulnerability is already being exploited in the wild.

    1000033
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    On May 7, 2026, Microsoft disclosed CVE-2026-35435, a critical elevation-of-privilege flaw in Azure AI Foundry—the cloud platform used by enterprises to build, train, and deploy AI models and agents. The vulnerability stems from improper access control in how the service…

    Post summary

    Microsoft has disclosed CVE‑2026‑35435, a critical elevation‑of‑privilege flaw in Azure AI Foundry due to improper access control, with no mention of PoC, exploit code, patch, or active exploitation.

    1000033
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Unpatched and Exploited: CVE-2026-35435 Breaks Azure AI Foundry Access Controls—Microsoft 365 Agents at Risk. On May 7, 2026, Microsoft disclosed CVE-2026-35435, a critical elevation-of-privilege flaw in Azure AI Foundry—the cloud platform used by enterprises to build,…

    Post summary

    The announcement highlights an unpatched critical privilege‑elevation flaw in Azure AI Foundry that is actively exploited, but no PoC, exploit code, or patch details are provided.

    1000037
    258 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-35435 is a watershed moment for AI security. It demonstrates that AI platform vulnerabilities now represent asymmetric risk: a single access control flaw can bridge the gap between a low-privileged attacker and organizational-wide data compromise.

    Post summary

    The text highlights the high-level risk implications of CVE-2026-35435, noting an access control flaw that enables organ-wide data compromise, but provides no PoC, exploit, patch, or active exploitation evidence.

    1000025
    258 followersView on X
  • kawn@kawn2020
    General

    #windowsupdate #microsoft つづき ・CVE-2026-33841 7.8 Windows カーネル ・CVE-2026-35416 7  WinSock 用 Windows Ancillary Function Driver ・CVE-2026-35417 7.8 Windows Win32K: ICOMP ・CVE-2026-35435 8.6 Azure AI Foundry M365 公開済みエージェント つづく…

    Post summary

    The tweet simply enumerates several Windows-related CVEs with their CVSS scores and affected components, without providing exploitation details, PoC code, or mitigation advice.

    10000109
    85 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-35435: Azure AI Foundry M365 Published Agents Privilege Escalation — What It Means for Your Business and How to Respond https://hubs.li/Q04h4Vpx0

    Post summary

    The text announces CVE‑2026‑35435 as a privilege escalation vulnerability affecting Azure AI Foundry M365 published agents, highlighting its business implications but providing no detailed technical, exploit, or patch information.

    0000037
    31 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35435 Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-35435 ----- Traducción: CVE-2026-35435 Control de acceso inapropiado en age… http://infoflow.cloud`

    Post summary

    The text announces CVE-2026-35435, detailing an improper access control flaw in Azure AI Foundry that allows privilege escalation; no PoC, exploit, or patch information is provided.

    0000023
    76 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftazure_ai_foundry---

Explore more