External risk intelligence

Attackers can gain admin control of Azure AI Foundry agents over the internet

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-35435

A critical flaw in Microsoft Azure AI Foundry agents lets anyone on the internet take over the service and access sensitive data. This requires immediate attention.

4Halo Surface Signal

Microsoft Azure Ai Foundry

External exposure likelihood

Halo Surface Signal score for CVE-2026-35435

Azure AI Foundry agents are cloud-based services designed to interact with users via Microsoft 365 interfaces. These agents operate as web-accessible services intended for user interaction within organizational workflows, which frequently places them in a position to be reachable over the network in standard enterprise deployments.

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in Azure AI Foundry M365 published agents allows an unauthorized attacker to gain elevated privileges. This issue could significantly impact systems that rely on these agents for sensitive operations.

  • Network reachable without authentication.
  • Allows full control over agent functions.
  • Potentially impacts business operations.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability over the network to gain unauthorized administrative control of Azure AI Foundry agents. By chaining this access control bypass with other potential weaknesses, an attacker could potentially execute arbitrary code or steal sensitive data within the M365 environment. This flaw could allow for broad compromise of connected systems and user information.

  • Network access required.
  • Target Azure AI Foundry agents.
  • Publicly accessible agent endpoint.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability presents a significant risk due to its critical severity and potential for remote exploitation without authentication. Attackers are likely to target this type of vulnerability because it offers a direct path to privilege escalation in cloud-based AI services, which are increasingly critical for business operations. The broad impact and ease of potential exploitation make it an attractive target.

  • Remote code execution possible.
  • No authentication required.
  • Cloud service impact.

Priority actions

Operational Fix

Recommended remediation, mitigation, and detection steps

Prioritize immediate containment for Azure AI Foundry M365 published agents due to critical unauthorized privilege escalation. Review logs for signs of exploitation and identify affected assets to assess exposure. If exploitation is confirmed or likely, isolate affected services.

  • Block all network access.
  • Monitor for unauthorized activity.
  • Investigate potential compromise.

Frequently asked questions

What are Azure AI Foundry M365 published agents?

Azure AI Foundry M365 published agents are cloud-based services designed to interact with users through Microsoft 365 interfaces. They are used within organizational workflows to provide AI-powered capabilities.

What weakness class does CVE-2026-35435 fall under?

CVE-2026-35435 is classified under CWE-284, which indicates an improper access control vulnerability. This means the system fails to properly restrict who can perform certain actions, allowing unauthorized access.

How could an attacker exploit CVE-2026-35435?

An attacker could exploit this vulnerability over a network without needing any authentication. The vulnerability allows for privilege escalation, potentially granting the attacker administrative control over the affected agents.

Who should care about this vulnerability given its external exposure?

Organizations using Azure AI Foundry M365 published agents should care about this vulnerability. The Halo Surface Signal indicates these agents are likely internet-facing, meaning they could be accessible and targeted by attackers from outside the organization's internal network.

What is the first step for responding to this threat?

Given the critical nature of this vulnerability, the immediate first step is to prioritize containment for Azure AI Foundry M365 published agents. This involves reviewing logs for any signs of exploitation and identifying all affected assets to understand the scope of potential exposure.

References