ZeroHour

CVE-2026-77909

niche

Insufficiently Protected Credentials in Microsoft Azure CycleCloud

CVSS 3.1
7.7 high
EPSS
<1%p46
Published
()
Modified
AI analysis

CVE-2026-77909 is a credential-protection flaw (CWE-522) in Microsoft Azure CycleCloud, Microsoft's tool for creating and managing HPC clusters in Azure, in which credentials are stored or transmitted with insufficient protection. A remote attacker who already holds a low-privileged authorized account can trigger the flaw over the network, with no user interaction required. Because the CVSS scope is changed with high confidentiality impact, the exposed credentials can likely be used in another security scope — for example, to retrieve or reuse secrets that grant access to additional resources beyond the immediate component — resulting in information disclosure, though integrity and availability are unaffected. Organizations running Azure CycleCloud to orchestrate HPC workloads in their Azure subscriptions are affected. There is no known public proof-of-concept, it is not in the CISA KEV catalog, EPSS is a modest 0.6% over 30 days, and no in-the-wild exploitation has been reported; a fix was distributed as part of Microsoft's September 2026 Patch Tuesday, which addressed 966 flaws.

What to do: Apply the Azure CycleCloud update from Microsoft's September 2026 Patch Tuesday to all CycleCloud application deployments in your Azure subscriptions, including standalone and cluster-attached instances. Since CycleCloud is customer-deployed, verify your installed build via the CycleCloud portal or CLI and update from the Azure Marketplace if outdated. As a precaution, audit and rotate credentials/API keys configured in CycleCloud, restrict network access to the application to trusted users, and review access logs for unusual credential retrieval by low-privileged accounts.

Affected
Microsoft Azure CycleCloud
Estimated exposure
nicheunknown; plausibly in the low thousands of enterprise HPC deployments at most — Azure CycleCloud is a specialized HPC cluster-management tool used by a minority of Azure customers and Microsoft publishes no install or user counts, so the affected population is likely limited to enterprises running HPC workloads in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.

Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

Patch Tuesday - September 2026

Microsoft's September 2026 Patch Tuesday fixes 999 CVEs, a record, with two zero-day privilege escalation flaws already exploited in the wild.

Microsoft published 974 own-product vulnerabilities plus 25 non-Microsoft CVEs, totaling 999 — the most CVEs Microsoft has ever released in a single day. Two flaws are exploited in the wild: CVE-2026-85880, an out-of-bounds write in Windows ALPC granting SYSTEM privileges, and CVE-2026-81963, an improper link resolution flaw in the Windows Update Stack also leading to SYSTEM. Chrome's V8 zero-day CVE-2026-85046 was patched in Edge on September 2, but Microsoft had not published a corresponding advisory, leaving uncertainty about other Chromium fixes in Edge. October 14 lifecycle changes end servicing for Windows 11 24H2 Home/Pro, Office 2021, and Exchange Server 2016/2019.

Rapid7 Blog · 7d agoVulnerability in the wildCVE-2026-85880CVE-2026-81963CVE-2026-85046+10 CVEs

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Microsoft's September 2026 Patch Tuesday fixes a record 966 flaws, including two Windows zero-days actively exploited to gain SYSTEM privileges.

Microsoft's September 2026 Patch Tuesday addresses a record 966 vulnerabilities, including 105 rated Critical, 81 of them remote code execution bugs. Two zero-days were actively exploited: a Windows Update Stack link-following flaw and a Windows ALPC heap-based buffer overflow, both allowing local elevation to SYSTEM privileges. The ALPC flaw was reported by Volexity and Proofpoint researchers, while the Update Stack flaw was credited to Romain Deperne and the Microsoft Threat Intelligence Centre. Microsoft shared no details on how the flaws were exploited in attacks.

BleepingComputer · 7d agoAdvisory in the wildCVE-2026-69805CVE-2026-58649CVE-2026-69806+27 CVEs1