AI analysis
CVE-2026-77909 is a credential-protection flaw (CWE-522) in Microsoft Azure CycleCloud, Microsoft's tool for creating and managing HPC clusters in Azure, in which credentials are stored or transmitted with insufficient protection. A remote attacker who already holds a low-privileged authorized account can trigger the flaw over the network, with no user interaction required. Because the CVSS scope is changed with high confidentiality impact, the exposed credentials can likely be used in another security scope — for example, to retrieve or reuse secrets that grant access to additional resources beyond the immediate component — resulting in information disclosure, though integrity and availability are unaffected. Organizations running Azure CycleCloud to orchestrate HPC workloads in their Azure subscriptions are affected. There is no known public proof-of-concept, it is not in the CISA KEV catalog, EPSS is a modest 0.6% over 30 days, and no in-the-wild exploitation has been reported; a fix was distributed as part of Microsoft's September 2026 Patch Tuesday, which addressed 966 flaws.
What to do: Apply the Azure CycleCloud update from Microsoft's September 2026 Patch Tuesday to all CycleCloud application deployments in your Azure subscriptions, including standalone and cluster-attached instances. Since CycleCloud is customer-deployed, verify your installed build via the CycleCloud portal or CLI and update from the Azure Marketplace if outdated. As a precaution, audit and rotate credentials/API keys configured in CycleCloud, restrict network access to the application to trusted users, and review access logs for unusual credential retrieval by low-privileged accounts.
Affected
| Microsoft Azure CycleCloud | — |
Estimated exposure
nicheunknown; plausibly in the low thousands of enterprise HPC deployments at most — Azure CycleCloud is a specialized HPC cluster-management tool used by a minority of Azure customers and Microsoft publishes no install or user counts, so the affected population is likely limited to enterprises running HPC workloads in…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.