CVE-2026-63508Patch(microsoft / planetary_computer)

LOWCVSS 10.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft planetary_computer systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • planetary_computer

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 7 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-08-07); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
planetary_computer

1 version affected across 1 product

Deep dive

Activity timeline8 mentions / 5d
01234Mentions · 2026-08-06: 1Mentions · 2026-08-07: 4Mentions · 2026-08-08: 1Mentions · 2026-08-09: 1Mentions · 2026-08-10: 1PoC Mentioned / Linked · 2026-08-07: 1Patch / Workaround · 2026-08-07: 2Patch / Workaround · 2026-08-08: 1Patch / Workaround · 2026-08-09: 1Patch / Workaround · 2026-08-10: 1Technical Details · 2026-08-07: 4Technical Details · 2026-08-08: 1Technical Details · 2026-08-09: 1Technical Details · 2026-08-10: 108-0608-0708-0808-0908-10
Signal classification4 categories
Patch
450.0%
Disclosure
225.0%
General
112.5%
PoC
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-08-061
General1
2026-08-074
Disclosure2Patch1PoC1
2026-08-081
Patch1
2026-08-091
Patch1
2026-08-101
Patch1
Full discourse8 posts
  • しーにゃ♪@公式@Syynya
    Patch

    Microsoft、Azure・Entra・Teams関連にCVSS最大値10.0を含む重大脆弱性を多数修正 Appleもネットワーク上の画面共有認証回避を修正(CVE-2026-63508,CVE-2026-56162)他 https://rocket-boys.co.jp/security-measures-lab/microsoft-apple-critical-vulnerability-patches-cve-2026-63508/ 月例以外で Microsoft がセキュリティパッチを出すときはホントヤバいときなので早急に対応を。

    Post summary

    The post announces that Microsoft and Apple have released patches for several high‑severity vulnerabilities, including CVEs with CVSS 10.0, and urges immediate action.

    1101098
    911 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Microsoft、Azure・Entra・Teams関連にCVSS最大値10.0を含む重大脆弱性を多数修正 Appleもネットワーク上の画面共有認証回避を修正(CVE-2026-63508,CVE-2026-56162)他 https://rocket-boys.co.jp/security-measures-lab/microsoft-apple-critical-vulnerability-patches-cve-2026-63508/ #セキュリティ対策Lab #security #securitynews #脆弱性

    Post summary

    The post announces that Microsoft Azure/Entra/Teams and Apple have applied patches for critical CVEs, including CVE‑2026‑63508, with details and a link to the vendor advisory.

    01010239
    515 followersView on X
  • Steve Waterhouse@Water_Steve
    Patch

    Pour votre information // For your information Bon weekend ! Correctifs hors-cycle (#OoB) menaçant envers les les produits logiciels de @Microsoft et @Apple déployés En provenance de l'article de @SecurityWeek ci-bas mentionné: "Trois de ces vulnérabilités, CVE-2026-63508, CVE-2026-56162 et CVE-2026-65667, ont un niveau de gravité maximal de 10/10. Quatre autres vulnérabilités, CVE-2026-50515 (RCE dans #Azure Service Bus), CVE-2026-62830 (EoP dans #Azure SRE Agent), CVE-2026-59115 (EoP dans #Entra Provisioning Service) et CVE-2026-50481 (EoP dans #ActiveDirectory) ont un score CVSS de 9,9/10. Ces quatre vulnérabilités sont exploitables à distance. Des correctifs visant à remédier à cette faille de sécurité ont été intégrés dans #macOS #Tahoe 26.6.1, #macOS #Sequoia 15.7.9 et #macOS #Sonoma 14.8.9" 20260807 - #Microsoft, #Apple Release Fresh #SecurityUpdates https://www.securityweek.com/microsoft-apple-release-fresh-security-updates/ #infosec #cybersecurity #secinfo #cybersecurite #cyberwar #cyberwarfare #OPSEC @infosecsw #criticalinfrastructure #infrastructureessentielle #patchmanagement #gestioncorrectifs #DQP #ASAP

    Post summary

    The post announces Microsoft and Apple’s out‑of‑cycle security updates for several high‑severity CVEs, highlighting RCE and elevation‑of‑privilege flaws, and notes that the fixes are already integrated into recent macOS releases.

    01010161
    3.9K followersView on X
  • Sami Laiho@samilaiho
    Patch

    Microsoft Planetary Computer Pro Elevation of Privilege Vulnerability URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-63508 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0

    Post summary

    Microsoft announced CVE‑2026‑63508 as a critical elevation‑of‑privilege flaw with an official fix; no PoC or exploitation details were disclosed.

    00010884
    30.6K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Microsoft Planetary Computer Pro GeoCatalog Missing Auth Privilege Escalation (CVE-2026-63508) Planetary Computer Pro (GeoCatalog) exposes a critical function without authentication checks, allowing unauthenticated remote requests over the network to invoke privileged operations and elevate privileges. Deployments with strict upstream auth enforcement in front of GeoCatalog are not directly exposed. 👉Affected: Microsoft Planetary Computer Pro (GeoCatalog) (versions unknown)

    Post summary

    Microsoft Planetary Computer Pro GeoCatalog exposes a critical function lacking authentication, leading to unauthenticated privilege escalation (CVE-2026-63508); mitigation involves enforcing upstream authentication.

    0000098
    282 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-63508 Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. https://www.cve.org/CVERecord?id=CVE-2026-63508

    Post summary

    CVE-2026-63508 reveals a missing authentication flaw in Microsoft Planetary Computer Pro that permits an unauthorized attacker to elevate privileges over a network.

    00000889
    57.9K followersView on X
  • SecNews@SecNews_GR
    PoC

    Microsoft Planetary Computer Pro: CVE-2026-63508 χωρίς έλεγχο ταυτότητας https://secn.ws/VqB66P

    Post summary

    CVE-2026-63508 is highlighted as a no‑authentication flaw, with a provided link that likely contains a proof‑of‑concept, but no exploit, patch, or active exploitation details are disclosed.

    00000190
    7.0K followersView on X
  • Windows Forum@windowsforum
    General

    🚨 Microsoft disclosed a Planetary Computer Pro elevation-of-privilege flaw with no patch, CVSS, exploit details, or mitigation. Enterprise admins get a CVE and a shrug. Great for security theater. https://windowsforum.com/security-alerts.84/cve-2026-63508-planetary-computer-pro-eop-has-no-patch.441883/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #EntraId #AzureRbac #Cve202663508 #PlanetaryComputerPro https://t.co/6p8kSOhMzX

    Post summary

    The tweet reports Microsoft’s disclosure of an elevation‑of‑privilege flaw in Planetary Computer Pro but provides no technical, exploit, patch, or active‑exploitation details.

    0000062
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftplanetary_computer---

Explore more