📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global phishing Cross-sector HIGH 2h Global apt Education CRITICAL 1h Global vulnerability Enterprise Software / ERP Systems CRITICAL 2h Global vulnerability IT Infrastructure CRITICAL 3h Global vulnerability Technology and Software Development HIGH 4h Global vulnerability Enterprise IT and Government CRITICAL 4h Global ransomware Multiple Sectors / Enterprise CRITICAL 5h Global general Technology and Legal MEDIUM 6h Global ransomware Financial Services / Cryptocurrency CRITICAL 6h Global general Industrial Control Systems / Operational Technology HIGH 7h Global phishing Cross-sector HIGH 2h Global apt Education CRITICAL 1h Global vulnerability Enterprise Software / ERP Systems CRITICAL 2h Global vulnerability IT Infrastructure CRITICAL 3h Global vulnerability Technology and Software Development HIGH 4h Global vulnerability Enterprise IT and Government CRITICAL 4h Global ransomware Multiple Sectors / Enterprise CRITICAL 5h Global general Technology and Legal MEDIUM 6h Global ransomware Financial Services / Cryptocurrency CRITICAL 6h Global general Industrial Control Systems / Operational Technology HIGH 7h Global phishing Cross-sector HIGH 2h Global apt Education CRITICAL 1h Global vulnerability Enterprise Software / ERP Systems CRITICAL 2h Global vulnerability IT Infrastructure CRITICAL 3h Global vulnerability Technology and Software Development HIGH 4h Global vulnerability Enterprise IT and Government CRITICAL 4h Global ransomware Multiple Sectors / Enterprise CRITICAL 5h Global general Technology and Legal MEDIUM 6h Global ransomware Financial Services / Cryptocurrency CRITICAL 6h Global general Industrial Control Systems / Operational Technology HIGH 7h
Vulnerabilities

CVE-2026-41094

High
CWE-94 — Weakness Type
Published: May 12, 2026  ·  Modified: May 19, 2026  ·  Source: NVD
CVSS v3
8.8
🔗 NVD Official
📄 Description (English)

Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network.

🤖 AI Executive Summary

CVE-2026-41094 is a critical code injection vulnerability in Microsoft Data Formulator that allows remote code execution without authentication. With a CVSS score of 8.8 and no patch currently available, this poses an immediate threat to organizations using this tool for data analysis and reporting. The vulnerability requires urgent mitigation through compensating controls and network segmentation until Microsoft releases a patch.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 19, 2026 11:48
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses significant risk to Saudi banking sector (SAMA-regulated institutions), government agencies (NCA oversight), and energy sector organizations (ARAMCO, downstream operators) that utilize Microsoft Data Formulator for financial analysis, reporting, and operational intelligence. Telecom operators (STC, Mobily) and healthcare providers using this tool for analytics are also at elevated risk. The lack of authentication requirement makes this particularly dangerous in environments with internet-facing instances.
🏢 Affected Saudi Sectors
Banking and Financial Services Government and Public Administration Energy and Utilities Telecommunications Healthcare Insurance Manufacturing
⚖️ Saudi Risk Score (AI)
8.5
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Inventory all instances of Microsoft Data Formulator across your organization and document their network exposure
2. Disable or restrict network access to Data Formulator instances immediately, limiting access to trusted internal networks only
3. Implement network segmentation to isolate Data Formulator servers from critical systems and data repositories
4. Enable enhanced logging and monitoring on all Data Formulator instances for suspicious code patterns and unusual data access

COMPENSATING CONTROLS:
5. Deploy Web Application Firewall (WAF) rules to detect and block code injection patterns targeting Data Formulator endpoints
6. Implement input validation and sanitization at the application layer if possible through configuration
7. Restrict user permissions to read-only access where feasible
8. Monitor for exploitation attempts using IDS/IPS signatures detecting code injection payloads

DETECTION RULES:
9. Alert on POST/PUT requests to Data Formulator API endpoints containing suspicious characters (backticks, ${}, eval, exec, system)
10. Monitor for unusual process spawning from Data Formulator service accounts
11. Track data exfiltration patterns and unauthorized file access from Data Formulator processes
12. Monitor for patch availability from Microsoft and apply immediately upon release
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. قم بحصر جميع نسخ Microsoft Data Formulator عبر مؤسستك وتوثيق تعرضها الشبكي
2. عطّل أو قيّد الوصول الشبكي إلى نسخ Data Formulator فوراً، مع تحديد الوصول للشبكات الداخلية الموثوقة فقط
3. طبّق فصل الشبكة لعزل خوادم Data Formulator عن الأنظمة الحرجة ومستودعات البيانات
4. فعّل السجلات المحسّنة والمراقبة على جميع نسخ Data Formulator للكشف عن أنماط الأكواد المريبة والوصول غير المعتاد للبيانات

الضوابط البديلة:
5. نشّر قواعد جدار تطبيقات الويب (WAF) للكشف عن أنماط حقن الأكواد وحجبها
6. طبّق التحقق من صحة المدخلات والتنظيف على مستوى التطبيق إن أمكن
7. قيّد صلاحيات المستخدمين للوصول للقراءة فقط حيث أمكن
8. راقب محاولات الاستغلال باستخدام توقيعات IDS/IPS

قواعد الكشف:
9. أصدر تنبيهات على طلبات POST/PUT تحتوي على أحرف مريبة
10. راقب عمليات غير عادية من حسابات خدمة Data Formulator
11. تتبع أنماط تسرب البيانات والوصول غير المصرح للملفات
12. راقب توفر التصحيحات من Microsoft وطبّقها فوراً عند الإصدار
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 - Management of technical vulnerabilities ECC 2024 A.14.2.1 - Secure development policy ECC 2024 A.12.3.1 - Configuration management
🔵 SAMA CSF
SAMA CSF ID.BE-5 - Organizational resilience SAMA CSF PR.DS-6 - Data is protected from unauthorized access SAMA CSF DE.CM-1 - The network is monitored to detect potential cybersecurity events
🟡 ISO 27001:2022
ISO 27001:2022 A.12.6.1 - Management of technical vulnerabilities ISO 27001:2022 A.14.2.1 - Secure development policy ISO 27001:2022 A.8.1.1 - Inventory of assets
🟣 PCI DSS v4.0.1
PCI DSS 6.2 - Ensure security patches are installed PCI DSS 6.5.1 - Injection flaws prevention PCI DSS 11.2 - Vulnerability scanning
📦 Affected Products / CPE 1 entries
microsoft:data_formulator
📊 CVSS Score
8.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionR — Required
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.8
CWECWE-94
EPSS0.07%
Exploit No
Patch ✗ No
Published 2026-05-12
Source Feed nvd
🇸🇦 Saudi Risk Score
8.5
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-94
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.