chiprook
← Security
SecuritySeptember 17, 2026, 21:36

A Prompt Injection Turned Into a Shell: Inside Semantic Kernel's Two RCE CVEs

Microsoft disclosed CVE-2026-26030 and CVE-2026-25592 in the Semantic Kernel framework: LLM output was passed to eval() in a vector search filter and to a file download path without validation, allowing code execution. Fixes were released in Python SDK 1.39.4 and .NET SDK 1.71.0.

A Prompt Injection Turned Into a Shell: Inside Semantic Kernel's Two RCE CVEs
#Microsoft#SemanticKernel
Read next
Security

Sekoia uncovers Exvicy, a new ClickFix MaaS built on ErrTraffic code

Security

Cyberattack hits University of Munich, student data at risk

Security

TASK#STOMP Windows backdoor steals documents, Wi-Fi passwords and screenshots

Security

CVE-2026-81657 in IBM Guardium: deserialization flaw rated 9.8