CVE-2026-23654Disclosure(microsoft / zero-shot-scfoundation)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft zero-shot-scfoundation systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network.

4.3/ 10 priority

Sources & remediation

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zero-shot-scfoundation

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 11 mentions across 8 observed days
  • Momentum state: rising

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 9 signals
  • Disclosure: 7 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-20); latest day: 1
  • 11 total mentions across 8 days

Affected systems

Vendors
Products
zero-shot-scfoundation

Deep dive

Activity timeline11 mentions / 8d
01223Mentions · 2026-03-10: 1Mentions · 2026-03-11: 2Mentions · 2026-03-14: 1Mentions · 2026-03-16: 1Mentions · 2026-03-25: 1Mentions · 2026-03-31: 1Mentions · 2026-04-20: 3Mentions · 2026-04-21: 1PoC Mentioned / Linked · 2026-03-11: 1PoC Mentioned / Linked · 2026-03-25: 1Exploit Tool / Code · 2026-03-25: 1Patch / Workaround · 2026-03-11: 1Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-14: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-20: 303-1003-1103-1403-1603-2503-3104-2004-21
Signal classification4 categories
Disclosure
763.6%
General
218.2%
Patch
19.1%
Exploit
19.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-101
Disclosure1
2026-03-112
Disclosure1Patch1
2026-03-141
Disclosure1
2026-03-161
Disclosure1
2026-03-251
Exploit1
2026-03-311
General1
2026-04-203
Disclosure3
2026-04-211
General1
Full discourse11 posts
  • SoyITPro@SoyITPro
    Patch

    🔒 Updates – Marzo 2026 Microsoft corrige 84 fallos, incluyendo 8 críticos en Windows, Office, SQL Server, .NET y Azure: 🛑 CVE-2026-26127 (.NET) – Denegación de servicio por lectura fuera de límites. 📊 CVE-2026-21262 (SQL Server) – Escalada de privilegios hasta SQLAdmin. 📄 CVE-2026-26113 (Office) – RCE por puntero no confiable (CVSS 8.4) 📄 CVE-2026-26110 (Office) – RCE por confusión de tipos, explotable vía Panel de Vista Previa. 📊 CVE-2026-26144 (Excel) – Divulgación de información sensible en generación web. 🌐 CVE-2026-23654 (GitHub/PyPI) – RCE por dependencia maliciosa en paquetes de terceros. #Security #Windows #Updates

    Post summary

    Microsoft issued patches for eight critical CVEs across Windows, Office, SQL Server, .NET, and Azure, addressing various vulnerabilities including DoS, privilege escalation, remote code execution, and information disclosure.

    0703131.3K
    12.3K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    CVE-2026-23654 — Dependency-confusion style RCE via malicious PyPI packages in build workflows. ⚠️ CVE-2026-23654: dependency confusion → RCE via malicious PyPI package. This is exactly why your build chain needs strict provenance. https://nvd.nist.gov/vuln/detail/CVE-2026-23654

    Post summary

    The post announces a dependency‑confusion RCE vulnerability (CVE‑2026‑23654) in package build pipelines, describing its mechanism, without indicating active exploitation, available exploits, or a patch.

    1001015
    1.0K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-48757 2 - CVE-2026-34621 3 - CVE-2026-35616 4 - CVE-2026-23654 5 - CVE-2026-5760 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A generic list of five trending CVEs with no additional context or technical information.

    00010507
    1.7K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    CVE-2026-23654 — Dependency-confusion style RCE via malicious PyPI packages in build workflows. ⚠️ CVE-2026-23654: dependency confusion → RCE via malicious PyPI package. This is exactly why your build chain needs strict provenance. https://nvd.nist.gov/vuln/detail/CVE-2026-23654

    Post summary

    The text announces CVE-2026-23654, detailing that malicious PyPI packages can induce remote code execution via dependency confusion in build workflows.

    0001015
    1.0K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    CVE-2026-23654 — Dependency-confusion style RCE via malicious PyPI packages in build workflows. ⚠️ CVE-2026-23654: dependency confusion → RCE via malicious PyPI package. This is exactly why your build chain needs strict provenance. https://nvd.nist.gov/vuln/detail/CVE-2026-23654

    Post summary

    The post announces CVE-2026-23654, outlining a dependency‑confusion RCE via malicious PyPI packages in build workflows, and directs readers to the NVD entry without providing PoC, exploit, or patch details.

    100002
    1.0K followersView on X
  • White Rabbitx@TheRabbitPy
    Exploit

    🚨 CVE-2026-23654 (CVSS 8.8) GitHub repo “zero-shot-scfoundation” dep confusion → RCE via malicious PyPI “geneformer”. Full system pwn on pip install. Patch v0.1.1! https://feedly.com/cve/security-advisories/microsoft/2026-03-10-march-2026-patch-tuesday-10-critical-vulnerabilities-amid-96-cve

    Post summary

    The post highlights a CVE‑2026‑23654 RCE caused by dependency confusion via a malicious PyPI package, includes patch availability, and showcases an exploitable scenario.

    0001065
    434 followersView on X
  • Aakash Rahsi@rahsi_aaka
    General

    CVE-2026-23654 | GitHub: Zero Shot SCFoundation Remote Code Execution Vulnerability https://www.aakashrahsi.online/post/cve-2026-23654 https://t.co/Cvx4YKDBQI

    Post summary

    The post references CVE-2026-23654 and links to external content, but offers no proof of concept, exploit code, active exploitation claims, or patch information.

    0000025
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23654 Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network. https://www.cve.org/CVERecord?id=CVE-2026-23654

    Post summary

    A newly reported CVE (CVE-2026-23654) in the zero‑shot‑scfoundation GitHub repository poses a remote code execution risk due to a vulnerability in a third‑party component.

    00000210
    56.7K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Zero-shot-scfoundation, Remote Code Execution, #CVE-2026-23654 (HIGH) https://dailycve.com/zero-shot-scfoundation-remote-code-execution-cve-2026-23654-high/

    Post summary

    The tweet announces CVE‑2026‑23654 as a high‑severity Remote Code Execution vulnerability in Zero‑shot‑scfoundation, linking to a DailyCVE article for further details.

    0000031
    168 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-23654 - Microsoft - GitHub Repo: Zero Shot scFoundation - https://www.redpacketsecurity.com/cve-alert-cve-2026-23654-microsoft-github-repo-zero-shot-scfoundation/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-23654 #microsoft #github-repo-zero-shot-scfoundation

    Post summary

    The post announces CVE-2026-23654 affecting Microsoft and points to a GitHub repo that may contain a proof‑of‑concept; no exploitation details or patches are mentioned.

    0000076
    3.5K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-23654: HIGH] Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network.#cve,CVE-2026-23654,#cybersecurity https://cvefind.com/CVE-2026-23654

    Post summary

    The tweet announces CVE‑2026‑23654, noting that a vulnerable third‑party component can enable remote code execution, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    0000028
    601 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftzero-shot-scfoundation---

Explore more