Oct 2026: Azure App Service Remote Code Execution Vulnerability
CVE-2026-77900 Published on October 8, 2026

Azure App Service Remote Code Execution Vulnerability
Missing authentication for critical function in Azure App Service allows an unauthorized attacker to execute code over a network.

Vendor Advisory NVD

Weakness Type

Missing Authentication for Critical Function

The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.


Products Associated with CVE-2026-77900

Want to know whenever a new CVE is published for Microsoft Azure App Service? stack.watch will email you.

 

Affected Versions

Microsoft Azure App Service for Linux Version - is affected by CVE-2026-77900