Remote Code Execution Vulnerability in Azure Orbital Spatio by Microsoft
CVE-2026-40412

10CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
22 May 2026

What is CVE-2026-40412?

A vulnerability in Azure Orbital Spatio allows the unrestricted upload of files with potentially dangerous types, enabling unauthorized attackers to execute arbitrary code via network connections. This serious flaw can lead to significant security breaches if not patched promptly. Users of Azure Orbital Spatio are advised to review vulnerability details and implement necessary security measures.

Affected Version(s)

Azure Orbital Spatio -

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.