CVE-2026-57969 — CVSS 8.8 (high): Missing authentication for critical function in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.
CVE-2026-77909 — CVSS 7.7 (high): Insufficiently protected credentials in Azure CycleCloud allows an authorized attacker to disclose information over a network.