Microsoft has disclosed CVE-2026-77900, a CVSS 9.8 critical flaw in Azure App Service for Linux: a critical function is missing authentication, which lets an unauthorized attacker execute code over a network.
What Is It
CVE-2026-77900 is a missing-authentication vulnerability in Azure App Service, classified as CWE-306 (Missing Authentication for Critical Function). Microsoft's description says a critical function in the service does not require authentication. As a result, an unauthorized attacker can execute code over a network.
Microsoft ([email protected]) assigned the CVE. NVD published it on 2026-10-08, and its status is currently "Received," which means NVD has not finished its own analysis yet.
Why It Matters
Microsoft rates the flaw CVSS 3.1 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. Broken down:
- Network-reachable: the attack vector is Network.
- Low complexity: no special conditions are needed to exploit it.
- No privileges required: the attacker does not need to be authenticated.
- No user interaction: no one has to click or open anything.
- High impact: confidentiality, integrity and availability are all rated High.
Remote code execution with no authentication and no user interaction is among the most serious classes of vulnerability.
Exploitation status: As of publication, CVE-2026-77900 is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, and there are no public reports of active exploitation.
What's Vulnerable
According to the affected-product data Microsoft supplied in the CVE record on CVE.org:
- Vendor: Microsoft
- Product: Azure App Service for Linux
- Versions: none listed; the version field is "-" and marked affected
In that same CVE record, Microsoft has tagged the CVE "exclusively-hosted-service." That tag means the vulnerable component runs only in Microsoft's cloud, not in software that customers install themselves. NVD does not list any affected CPEs.
Patch Status
Neither the NVD entry nor the CVE record on CVE.org lists a fixed version, remediation guidance, or required customer action. Because CVE-2026-77900 is not in KEV, there is also no CISA remediation deadline.
The "exclusively-hosted-service" tag usually means the vendor fixes the issue on its own side, but Microsoft has not yet publicly confirmed that a fix is in place for this CVE. Azure App Service for Linux customers should check the MSRC Security Update Guide entry to see whether Microsoft has fixed it already or whether they need to do anything.
Sources
- Microsoft Security Response Center: CVE-2026-77900
- CVE.org: CVE-2026-77900 record (source of the "exclusively-hosted-service" tag and the "-" version field)
- NVD: CVE-2026-77900
- CISA Known Exploited Vulnerabilities Catalog (no entry for this CVE at time of writing)