CVE-2026-21537Disclosure(microsoft / defender_for_endpoint)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft defender_for_endpoint systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • defender_for_endpoint

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-02-10); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
defender_for_endpoint

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-10: 1Mentions · 2026-02-11: 1Mentions · 2026-03-11: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-02-10: 1Technical Details · 2026-03-11: 102-1002-1103-11
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-101
Disclosure1
2026-02-111
Disclosure1
2026-03-111
Patch1
Full discourse3 posts
  • Doctor Kloud@doctorkloud
    Patch

    L'extension Linux de Defender for Endpoint permet l'exécution de code à distance via injection — depuis le réseau adjacent, sans authentification. Réseau local compromis, la protection devient vecteur d'attaque. Patchez l'extension en priorité sur vos flottes Linux. #CVE https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21537

    Post summary

    The post announces a RCE vulnerability in the Defender for Endpoint Linux extension, urging users to patch promptly.

    0101048
    13 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting Microsoft Defender for Endpoint for Linux (CVE-2026-21537) https://vuldb.com/?id.345304

    Post summary

    The message reports a new vulnerability CVE‑2026‑21537 affecting Microsoft Defender for Endpoint for Linux with an increased severity rating, but provides no further technical details, fixes, or evidence of exploitation.

    0000076
    2.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21537 Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network. https://www.cve.org/CVERecord?id=CVE-2026-21537

    Post summary

    CVE‑2026‑21537 is a code injection flaw in Microsoft Defender for Linux that permits unauthorized code execution over an adjacent network; no PoC, exploit, patch, or active exploitation is reported.

    00000154
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftdefender_for_endpoint-linux-

Explore more