ThreatCluster

Multiple CVEs Disclosed in Azure Services

First seen 9 Sep 2026, 20:13 UTC Api.Msrc.Microsoftwww.cve.org 22

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities were disclosed in Microsoft Azure services. CVE-2026-45499 involves a server-side request forgery (SSRF) in Azure OpenAI, allowing privilege escalation for authorized attackers. This vulnerability has been fully mitigated, requiring no action from users. CVE-2026-77909 pertains to insufficiently protected credentials in Azure CycleCloud, which could lead to credential disclosure over a network. The latter vulnerability was published on September 8, 2026, and affects Azure CycleCloud users. Microsoft has not reported any active exploitation for either vulnerability, and both have been addressed in their respective advisories.

Key Points: • CVE-2026-45499 allows privilege escalation via SSRF in Azure OpenAI. • CVE-2026-77909 exposes credentials in Azure CycleCloud. • Both vulnerabilities have been mitigated with no reported active exploitation.

Ask AI about this cluster

Timeline

2026-07-02
CVE-2026-45499 released
Microsoft disclosed a server-side request forgery vulnerability in Azure OpenAI, which has been fully mitigated.
Api.Msrc.Microsoft
2026-09-08
CVE-2026-77909 published
Insufficiently protected credentials in Azure CycleCloud were disclosed, allowing potential credential disclosure.
Api.Msrc.Microsoft
2026-09-09
CVE-2026-45499 updated
Microsoft confirmed that CVE-2026-45499 has been fully mitigated and requires no user action.
Api.Msrc.Microsoft