AI analysis
CVE-2026-70352 is a missing-authentication flaw (CWE-306) in Microsoft Azure AI Language, where a critical function can be reached without any credential check. An attacker triggers it by sending unauthenticated network requests to the affected Azure AI Language service, and per the CVSS score (AV:N/AC:L/PR:N/UI:N/S:C) the weakness is trivially exploitable remotely with no privileges or user interaction required. Because the impact is scoped-changed (S:C) with high confidentiality, integrity, and availability impact, a successful attacker gains elevated privileges within the service context, potentially reaching resources beyond the intended trust boundary. Any organization using the Azure AI Language cloud service is affected; as a Microsoft-managed service it was addressed through Microsoft's September 2026 security updates. There is currently no evidence of in-the-wild exploitation, no known public proof-of-concept, it is not on the CISA KEV list, and EPSS estimates only a 0.6% chance of exploitation in the next 30 days.
What to do: Because Azure AI Language is a Microsoft-managed service, confirm via the Azure Service Health portal or Microsoft's September 2026 advisory that your tenant has received the patched service update — no customer-side patching should be required for the cloud service. Review Azure AI Language access logs for anomalous or unexpected unauthenticated requests, and as defense-in-depth restrict endpoints with network controls such as private endpoints, firewalls, or restricted network access rules.
Affected
| Microsoft Azure AI Language (cloud service) | — |
Estimated exposure
largeroughly 100,000–1,000,000 users/tenant applications (managed multi-tenant Azure service; exact counts not published) — Azure AI Language is a widely used managed Azure AI service consumed by many organizations for text analytics and natural-language workloads, so exposure scales with Azure's large multi-tenant customer base rather than self-managed…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.