Advisory · CVE-2026-77900
Unauthenticated code execution in Azure App Service for Linux
A missing authentication check on a critical function in Azure App Service for Linux let attackers run code over the network without any credentials, rated critical at CVSS 9.8.
- Vendor
- Microsoft
- Product
- Azure App Service for Linux
- Identifier / CWE
- CVE-2026-77900
CWE-306 - Action timing
- Immediate
Explain it like I’m five
The front door of the building had no lock on the one door that opens the vault. Anyone walking by could walk in and run the machines.
- 01No credentials needed
An unauthenticated attacker reaches the vulnerable function over the network.
- 02Authentication skipped
The critical function does not require authentication.
- 03Code runs
The attacker executes arbitrary code with full confidentiality, integrity, and availability impact.
What happened
Microsoft disclosed CVE-2026-77900 in Azure App Service for Linux on October 8, 2026. A critical function was missing authentication, letting an unauthenticated attacker execute code over the network. It scores 9.8 on CVSS 3.1 (network, low complexity, no privileges or user interaction required, full impact on confidentiality, integrity, and availability). NVD marks the entry as exclusively a hosted-service issue, so the fix lands on Microsoft’s side.
What to do
- No customer patch exists to apply; Microsoft remediates the service.
- Assume any data handled by your App Service apps was potentially reachable: inventory secrets, connection strings, and data the apps process.
- Review Azure activity and diagnostics logs for anomalous requests or outbound connections around October 8, 2026.
- Rotate credentials and tokens used by affected App Service workloads if misuse cannot be excluded.
- Watch for a Microsoft post-incident notice with exposure details.
Management note
This is the worst-case cloud scenario: unauthenticated remote code execution in a managed service your applications live on, with no patch you can install yourself. Treat it as an exposure-assessment exercise, not a patching one, and make credential rotation the default until Microsoft confirms blast radius.