CVE-2026-77909: Azure CycleCloud Information Disclosure Vulnerability
Overview
- Severity
- High (CVSS 7.7)
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N/E:U/RL:O/RC:C
- Category
- Information Disclosure
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2026-Sep
- Released
- 2026-09-08
Description
Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.
FAQ
What type of information could be disclosed by this vulnerability?
Exploiting this vulnerability could allow the disclosure of credentials.
Affected Products (1)
Azure
Security Updates (1)
Acknowledgments
XBREACH TEAM with <a href="https://xbreach.ai/">XBreach.ai</a>
Revision History
- 2026-09-08: Information published.