ZeroHour

CVE-2026-70352

large

Unauthenticated Privilege Elevation in Microsoft Azure AI Language

CVSS 3.1
10.0 critical
EPSS
<1%p48
Published
()
Modified
AI analysis

CVE-2026-70352 is a missing-authentication flaw (CWE-306) in Microsoft Azure AI Language, where a critical function can be reached without any credential check. An attacker triggers it by sending unauthenticated network requests to the affected Azure AI Language service, and per the CVSS score (AV:N/AC:L/PR:N/UI:N/S:C) the weakness is trivially exploitable remotely with no privileges or user interaction required. Because the impact is scoped-changed (S:C) with high confidentiality, integrity, and availability impact, a successful attacker gains elevated privileges within the service context, potentially reaching resources beyond the intended trust boundary. Any organization using the Azure AI Language cloud service is affected; as a Microsoft-managed service it was addressed through Microsoft's September 2026 security updates. There is currently no evidence of in-the-wild exploitation, no known public proof-of-concept, it is not on the CISA KEV list, and EPSS estimates only a 0.6% chance of exploitation in the next 30 days.

What to do: Because Azure AI Language is a Microsoft-managed service, confirm via the Azure Service Health portal or Microsoft's September 2026 advisory that your tenant has received the patched service update — no customer-side patching should be required for the cloud service. Review Azure AI Language access logs for anomalous or unexpected unauthenticated requests, and as defense-in-depth restrict endpoints with network controls such as private endpoints, firewalls, or restricted network access rules.

Affected
Microsoft Azure AI Language (cloud service)
Estimated exposure
largeroughly 100,000–1,000,000 users/tenant applications (managed multi-tenant Azure service; exact counts not published) — Azure AI Language is a widely used managed Azure AI service consumed by many organizations for text analytics and natural-language workloads, so exposure scales with Azure's large multi-tenant customer base rather than self-managed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

Patch Tuesday - September 2026

Microsoft's September 2026 Patch Tuesday fixes 999 CVEs, a record, with two zero-day privilege escalation flaws already exploited in the wild.

Microsoft published 974 own-product vulnerabilities plus 25 non-Microsoft CVEs, totaling 999 — the most CVEs Microsoft has ever released in a single day. Two flaws are exploited in the wild: CVE-2026-85880, an out-of-bounds write in Windows ALPC granting SYSTEM privileges, and CVE-2026-81963, an improper link resolution flaw in the Windows Update Stack also leading to SYSTEM. Chrome's V8 zero-day CVE-2026-85046 was patched in Edge on September 2, but Microsoft had not published a corresponding advisory, leaving uncertainty about other Chromium fixes in Edge. October 14 lifecycle changes end servicing for Windows 11 24H2 Home/Pro, Office 2021, and Exchange Server 2016/2019.

Rapid7 Blog · 7d agoVulnerability in the wildCVE-2026-85880CVE-2026-81963CVE-2026-85046+10 CVEs

The September 2026 Security Update Review

ZDI's September 2026 Microsoft update review lists two already-exploited Windows EoP zero-days and dozens of critical RCEs across Office, SQL Server, and Windows services.

The review catalogs Microsoft's September 2026 fixes, marking CVE-2026-85880 (Windows ALPC) and CVE-2026-81963 (Windows Update Stack) as already exploited elevation-of-privilege issues. It also lists critical RCE flaws in Office, Word, Excel, PowerPoint, Outlook, SQL Server, Windows DNS, DHCP and Failover Cluster, plus graphics component RCEs. Azure-side fixes include Entra ID, Copilot Studio, Azure AI Language and Azure AD B2C elevation-of-privilege flaws.