Act nowDisclosed

Advisory · CVE-2026-77900

Unauthenticated code execution in Azure App Service for Linux

A missing authentication check on a critical function in Azure App Service for Linux let attackers run code over the network without any credentials, rated critical at CVSS 9.8.

Vendor
Microsoft
Product
Azure App Service for Linux
Identifier / CWE
CVE-2026-77900
CWE-306
Action timing
Immediate
ELI5

Explain it like I’m five

The front door of the building had no lock on the one door that opens the vault. Anyone walking by could walk in and run the machines.

SIMPLIFIED_ATTACK_PATH03 STEPS
  1. 01No credentials needed

    An unauthenticated attacker reaches the vulnerable function over the network.

  2. 02Authentication skipped

    The critical function does not require authentication.

  3. 03Code runs

    The attacker executes arbitrary code with full confidentiality, integrity, and availability impact.

What happened

Microsoft disclosed CVE-2026-77900 in Azure App Service for Linux on October 8, 2026. A critical function was missing authentication, letting an unauthenticated attacker execute code over the network. It scores 9.8 on CVSS 3.1 (network, low complexity, no privileges or user interaction required, full impact on confidentiality, integrity, and availability). NVD marks the entry as exclusively a hosted-service issue, so the fix lands on Microsoft’s side.

What to do

  1. No customer patch exists to apply; Microsoft remediates the service.
  2. Assume any data handled by your App Service apps was potentially reachable: inventory secrets, connection strings, and data the apps process.
  3. Review Azure activity and diagnostics logs for anomalous requests or outbound connections around October 8, 2026.
  4. Rotate credentials and tokens used by affected App Service workloads if misuse cannot be excluded.
  5. Watch for a Microsoft post-incident notice with exposure details.

Management note

This is the worst-case cloud scenario: unauthenticated remote code execution in a managed service your applications live on, with no patch you can install yourself. Treat it as an exposure-assessment exercise, not a patching one, and make credential rotation the default until Microsoft confirms blast radius.