CVE-2026-41104Disclosure(microsoft / planetary_computer)

MEDIUMCVSS 7.5 · HIGH

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch microsoft planetary_computer systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • planetary_computer

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-05-23); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
planetary_computer

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-05-23: 3Mentions · 2026-05-27: 1Mentions · 2026-06-07: 1Mentions · 2026-06-08: 1Active Exploitation · 2026-05-23: 1Patch / Workaround · 2026-05-23: 1Patch / Workaround · 2026-05-27: 1Technical Details · 2026-05-23: 1Technical Details · 2026-05-27: 105-2305-2706-0706-08
Signal classification4 categories
Disclosure
233.3%
General
233.3%
Active Exploitation
116.7%
Patch
116.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-233
Active Exploitation1Disclosure2
2026-05-271
Patch1
2026-06-071
General1
2026-06-081
General1
Full discourse6 posts
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【緊急】CVE-2026-41104 Microsoft Planetary Computer Proに深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/06/06/cve-2026-41104-microsoft-planetary-computer-pro/ #IT #Security #cybersecurity

    Post summary

    The brief announcement flags CVE-2026-41104 as a serious issue in Microsoft Planetary Computer Pro but provides no details on exploitation, PoC, patching, or technical specifics.

    0001044
    209 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【緊急】CVE-2026-41104 Microsoft Planetary Computer Proに深刻な脆弱性|即時対応が必要 https://www.cybernote.click/2026/06/06/cve-2026-41104-microsoft-planetary-computer-pro/ #IT #Security #cybersecurity

    Post summary

    The tweet announces CVE‑2026‑41104 as a serious vulnerability in Microsoft Planetary Computer Pro but provides no technical details, PoC, exploit, or patch information.

    0000040
    209 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-41104 (CVSS 10.0) - Deserialization flaw in Microsoft Planetary Computer Pro enables unauthenticated remote attackers to disclose sensitive information. Network-exploitable, no user interaction required. Patch immediately. #CVE #PatchNow #CyberSecurity https://t.co/clhSpwgU3J

    Post summary

    The tweet announces CVE‑2026‑41104 as a critical deserialization flaw and urges an immediate patch, without indicating PoC, active exploitation, or debunking.

    0000039
    30 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    ⚠️ Attackers are actively exploiting CVE-2026-41104 in Microsoft Planetary Computer Pro—this vulnerability lets them access sensitive data. Patch now to prevent unauthorized access. #NerdieNews #CyberSecurity #Vulnerability https://t.co/KQO0027QMs

    Post summary

    The tweet claims attackers are actively exploiting CVE-2026-41104 in Microsoft Planetary Computer Pro to access sensitive data and urges users to patch immediately.

    0000045
    64 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41104 Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network. https://www.cve.org/CVERecord?id=CVE-2026-41104

    Post summary

    The post references CVE‑2026‑41104, describing a deserialization flaw that permits an attacker to disclose data over a network, without providing any PoC, exploit, patch, or active exploitation details.

    00000167
    57.5K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Microsoft Planetary Computer Pro (CVE-2026-41104) https://vuldb.com/vuln/365293

    Post summary

    A severe vulnerability for Microsoft Planetary Computer Pro (CVE-2026-41104) was disclosed; the post links to a vulnerability database but offers no further technical or mitigation details.

    0000066
    2.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftplanetary_computer---

Explore more