CVE-2026-77909: Azure CycleCloud Information Disclosure Vulnerability
Published Sep 8, 2026
·Updated
Azure CycleCloud Information Disclosure Vulnerability
Other sources
Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.
— Microsoft
Affected Software
1 affected componentFixes available
Microsoft Azure CycleCloud 8.9.2<8.9.2
8.9.2
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.9.2
Event History
Sep 8, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:13 PM
Data Sourced
via MITRE·05:13 PM
DescriptionSeverity
Data Sourced
via NVD·06:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker must already be authorized, requiring low privileges. Exploitation can be performed over a network and does not require user interaction.
2
What is the likely security impact?
Successful exploitation can disclose information, with a high confidentiality impact. The provided scoring indicates no direct integrity or availability impact.
3
Which deployment is identified as affected?
The affected software listed is Microsoft Azure CycleCloud version 8.9.2.