The Authentication Gap Is the Real AI Infrastructure Crisis
CVE-2026-82526 (CVSS 9.8), CVE-2026-85695 (CVSS 9.4), and CVE-2026-85620 (CVSS 9.2) all shipped this week without default authentication. Add Microsoft’s September 3 batch – nine identity CVEs, two at CVSS 10.0 – and the picture stops looking like a series of isolated bugs. These are not incidental coding errors; they are structural failures in how AI…