CVE-2026-23652Disclosure(microsoft / power_pages)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft power_pages systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • power_pages

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-05-23); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
power_pages

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-05-23: 2Mentions · 2026-05-27: 2Mentions · 2026-05-28: 1Mentions · 2026-05-29: 1Patch / Workaround · 2026-05-27: 2Technical Details · 2026-05-23: 1Technical Details · 2026-05-27: 105-2305-2705-2805-29
Signal classification3 categories
Disclosure
233.3%
Patch
233.3%
General
233.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-232
Disclosure2
2026-05-272
Patch2
2026-05-281
General1
2026-05-291
General1
Full discourse6 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    ثغرة خطيره في Microsoft Power Pages CVE-2026-23652 | 🔴 CRITICAL 10.0 اغلاق الثغره تم من قبل مايكروسفت لآن الخدمة سحابية لكن يفضل توجيه فريق SOC بفحص سجلات الاحداث احتياطا والبحث عن اي نشاط مشبوه

    Post summary

    Microsoft has closed CVE-2026-23652 for Power Pages as a critical security fix; SOC teams are advised to review logs for any anomalous activity.

    14118107.5K
    50.0K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-55182 2 - CVE-2026-5194 3 - CVE-2026-48095 4 - CVE-2026-23652 5 - CVE-2026-45585 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply enumerates the top 5 trending CVEs without providing technical details, exploitation status, or patch information.

    00010135
    1.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-1999-0997 2 - CVE-2026-45659 3 - CVE-2026-23652 4 - CVE-2026-45585 5 - CVE-2024-52577 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely enumerates trending CVE identifiers with no additional technical, exploit, or mitigation details.

    00010125
    1.7K followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-23652 - CVSS 10.0 Command injection in Microsoft Power Pages allows unauthenticated remote code execution. No user interaction required. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/L48mtn8m4R

    Post summary

    The tweet alerts about a critical CVE-2026-23652 involving command injection that allows unauthenticated RCE and urges users to apply the patch immediately.

    0000048
    30 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23652 Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a ne… https://www.cve.org/CVERecord?id=CVE-2026-23652

    Post summary

    The post announces a new Microsoft Power Pages command injection vulnerability (CVE‑2026‑23652) without providing proof of exploitation, PoC code, or patch details.

    00000165
    57.5K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for Microsoft Power Pages (CVE-2026-23652) https://vuldb.com/vuln/365292

    Post summary

    A new CVE (CVE‑2026‑23652) for Microsoft Power Pages has been disclosed with increased severity, but no further technical details, exploits, or mitigations are provided.

    0000062
    2.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftpower_pages---

Explore more