cve 2026 35435

  1. CVE-2026-35435: Critical Azure AI Foundry Privilege Escalation in M365 Agents (No Patch)

    Microsoft disclosed CVE-2026-35435 on May 7, 2026, as a critical Azure AI Foundry elevation-of-privilege vulnerability in Microsoft 365 published agents, caused by improper access control and already mitigated by Microsoft with no customer action required. That is the comforting version of the...