Back to vendor advisories
Microsoft Security Response CenterCVE-2026-77900

Azure App Service Remote Code Execution Vulnerability

CriticalVendor CVSS 9.8 / 10 1 CVE Published Oct 8, 2026 at 7:00 AM UTC

Summary

Missing authentication for critical function in Azure App Service allows an unauthorized attacker to execute code over a network.

Products covered

  • Azure App Service for Linux

Remediation

Separate remediation guidance was not included in the collected bulletin.

CVEs in this advisory 1

Updates

  1. Published by Microsoft Security Response Center

    The publication date reported by the vendor.

  2. Added to SecurityAlert

    We collected the advisory from the official source.