Junglewise Threat Intelligence

CVE-2026-77909: Microsoft Azure CycleCloud credential exposure over network

CVE-2026-77909 · Severity: high · CVSS 7.7 · Published 2026-09-08

Executive brief

Azure CycleCloud is a cluster management tool used by enterprises to deploy and manage high-performance computing workloads in the cloud. Insufficiently protected credentials in the product can allow an authenticated user to intercept and disclose sensitive authentication material over the network, potentially leading to unauthorized access to computing resources and data.

Technical details

The vulnerability stems from insufficiently protected credential storage or transmission in Azure CycleCloud. An authorized attacker with network access can intercept and disclose credentials over the network. The attack requires prior authentication or authorized access to the system, and results in information disclosure that could facilitate further compromise of the cluster or related cloud resources. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Azure CycleCloud

Timeline

  • 2026-09-08: disclosed

References

Related threats