CVE-2026-26125Disclosure(microsoft / payment_orchestrator_service)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch microsoft payment_orchestrator_service systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Payment Orchestrator Service Elevation of Privilege Vulnerability

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • payment_orchestrator_service

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 11 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • Peaked 5d ago at 3 mentions (2026-03-06); latest day: 2
  • 11 total mentions across 7 days

Affected systems

Vendors
Products
payment_orchestrator_service

1 version affected across 1 product

Deep dive

Activity timeline11 mentions / 7d
01223Mentions · 2026-03-05: 1Mentions · 2026-03-06: 3Mentions · 2026-03-07: 2Mentions · 2026-03-11: 1Mentions · 2026-03-18: 1Mentions · 2026-03-27: 1Mentions · 2026-03-29: 2Active Exploitation · 2026-03-18: 1Patch / Workaround · 2026-03-07: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-03-29: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 2Technical Details · 2026-03-11: 1Technical Details · 2026-03-18: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-29: 203-0503-0603-0703-1103-1803-2703-29
Signal classification4 categories
Disclosure
436.4%
General
327.3%
Patch
327.3%
Active Exploitation
19.1%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-051
General1
2026-03-063
Disclosure3
2026-03-072
General1Patch1
2026-03-111
General1
2026-03-181
Active Exploitation1
2026-03-271
Patch1
2026-03-292
Disclosure1Patch1
Full discourse11 posts
  • White Rabbitx@TheRabbitPy
    Patch

    ⚙️ CVE-2026-26125 (Microsoft Payment Orchestrator): 8.6 CRIT missing auth on critical function—priv escalation. Patch: March 2026 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26125 https://nvd.nist.gov/vuln/detail/CVE-2026-26125 https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-march-2026/

    Post summary

    Microsoft Payment Orchestrator CVE-2026-26125 is a critical privilege‑escalation flaw due to missing authentication, with a vendor patch released in March 2026.

    1001052
    492 followersView on X
  • White Rabbitx@TheRabbitPy
    Disclosure

    💳 CVE-2026-26125 (MS Payment Orchestrator): 8.6 EoP missing auth for critical func. No interaction needed. https://nvd.nist.gov/vuln/detail/CVE-2026-26127 *(Note: Related to Patch Tuesday)

    Post summary

    The post announces a new CVE with technical details but provides no evidence of exploitation or patch information.

    1001059
    492 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #microsoft #定例外 2026. 3. 6 決済オーケストレーション サービスの特権昇格の脆弱性 CVE-2026-26125 Security Vulnerability リリース日: Mar 6, 2026 - マイクロソフト https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26125

    Post summary

    Microsoft has released a patch for CVE-2026-26125, a privilege‑elevation flaw in its Payment Orchestration Service, and directs users to the Microsoft Security Response Center for details.

    10100111
    89 followersView on X
  • White Rabbitx@TheRabbitPy
    Patch

    🎛️ Payment Orchestrator EoP (CVE-2026-26125) Critical priv-esc (CVSS 8.6) in MS payment service. Financial infra shops: Check exposure, patch yesterday. https://www.thezdi.com/blog/2026/3/10/the-march-2026-security-update-review #Microsoft #CVE

    Post summary

    The post highlights a critical privilege escalation flaw (CVE-2026-26125) in Microsoft's Payment Orchestrator and urges immediate patching, indicating a patch-focused advisory.

    0001067
    492 followersView on X
  • kawn@kawn2020
    General

    #windowsupdate #microsoft -対象外:1 件 ・CVE-2026-26125 8.6 決済オーケストレーション サービス -CVSS 基本値が 9.8 以上のもの:1 件 ・CVE-2026-21536 9.8 マイクロソフト デバイス価格プログラム

    Post summary

    The tweet simply lists two Microsoft CVEs with high CVSS scores, offering no further information on exploitation, remediation, or availability of PoC.

    1000054
    89 followersView on X
  • Raed alroomi@master_roomi
    Active Exploitation

    ثغرة Pay-Orchestrator (CVE-2026-26125) تم رصد نشاط هجومي استهدف أنظمة معالجة الدفع التي تعتمد على خدمة (Payment Orchestrator) وهي ثغرة "رفع امتيازات (CVSS 8.6) تسمح للمهاجمين بالتحكم في تدفقات الأموال الرقمية، مما وضع المؤسسات المالية العالمية في حالة استنفار @CentralBank_KW

    Post summary

    CVE-2026-26125 is a privilege‑escalation flaw in Pay‑Orchestrator that is actively exploited against payment‑processing systems, threatening global financial institutions.

    00000144
    12.8K followersView on X
  • kawn@kawn2020
    General

    #securityupdate #microsoft #定例外 CVE-2026-26125 Security Vulnerability 影響: 特権の昇格 最大深刻度: 緊急 CVSS:3.1 8.6 / 7.7 悪用可能性 ・一般に公開: No ・悪用: No ・Exploitability assessment: 対象外 https://x.com/kawn2020/status/2030113613734916395

    Post summary

    The tweet offers a concise security update on CVE‑2026‑26125, noting it as a privilege‑escalation vulnerability with high severity, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000060
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26125 Payment Orchestrator Service Elevation of Privilege Vulnerability https://www.cve.org/CVERecord?id=CVE-2026-26125

    Post summary

    The text announces a newly recorded CVE (CVE‑2026‑26125) for a Payment Orchestrator Service elevation‑of‑privilege flaw, linking to the official CVE record.

    00000185
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-26125 - High Payment Orchestrator Service Elevation of Privilege Vulnerability https://www.thehackerwire.com/vulnerability/CVE-2026-26125/ https://t.co/8Fym7hX0vd

    Post summary

    The tweet announces CVE‑2026‑26125, an elevation‑of‑privilege vulnerability in a Payment Orchestrator Service, and directs readers to a security article; it provides the vulnerability type and severity but no evidence of exploitation, PoC, or patch information.

    0000047
    125 followersView on X
  • dbugs@ptdbugs
    Disclosure

    Payment Orchestrator Service Elevation of Privilege Vulnerability CVE: CVE-2026-26125 Vendor: Microsoft Product: Payment Orchestrator Service CVSS: 8.6 Credits: n/a Description: Payment Orchestrator Service Elevation of Privilege Vulnerability References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-26125 • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26125 #dbugs_vuln

    Post summary

    The post announces CVE‑2026‑26125, an elevation‑of‑privilege flaw with CVSS 8.6 in Microsoft’s Payment Orchestrator Service, but provides no exploitation details, PoC, or patch information.

    0000086
    551 followersView on X
  • CVEFind.com@CveFindCom
    General

    [CVE-2026-26125: HIGH] Payment Orchestrator Service Elevation of Privilege Vulnerability#cve,CVE-2026-26125,#cybersecurity https://cvefind.com/CVE-2026-26125

    Post summary

    The tweet only references CVE-2026-26125 with a high severity label and a link, but provides no technical, proof-of-concept, exploit, or mitigation details.

    0000051
    596 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftpayment_orchestrator_service---

Explore more