CVE-2026-25592Disclosure

HIGHCVSS 9.9 · CRITICAL

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.71.0, an Arbitrary File Write vulnerability has been identified in Microsoft's Semantic Kernel .NET SDK, specifically within the SessionsPythonPlugin. The problem has been fixed in Microsoft.SemanticKernel.Core version 1.71.0. As a mitigation, users can create a Function Invocation Filter which checks the arguments being passed to any calls to DownloadFileAsync  or UploadFileAsync and ensures the provided localFilePath is allow listed.

6.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 57 mentions across 32 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 17 signals
  • Technical details provided in 47 signals
  • Disclosure: 31 classified signals
  • General: 9 classified signals
  • Peaked 24d ago at 6 mentions (2026-05-10); latest day: 1
  • 57 total mentions across 32 days

Deep dive

Activity timeline57 mentions / 32d
02356Mentions · 2026-02-06: 4Mentions · 2026-02-07: 2Mentions · 2026-02-10: 1Mentions · 2026-02-11: 1Mentions · 2026-03-18: 1Mentions · 2026-05-06: 1Mentions · 2026-05-08: 1Mentions · 2026-05-10: 6Mentions · 2026-05-11: 2Mentions · 2026-05-12: 1Mentions · 2026-05-13: 1Mentions · 2026-05-16: 1Mentions · 2026-05-17: 3Mentions · 2026-05-18: 1Mentions · 2026-05-21: 1Mentions · 2026-05-22: 2Mentions · 2026-05-24: 1Mentions · 2026-05-25: 3Mentions · 2026-05-27: 1Mentions · 2026-05-28: 1Mentions · 2026-05-31: 1Mentions · 2026-06-07: 2Mentions · 2026-06-10: 1Mentions · 2026-06-17: 1Mentions · 2026-06-19: 3Mentions · 2026-06-21: 3Mentions · 2026-06-24: 1Mentions · 2026-06-25: 1Mentions · 2026-06-27: 4Mentions · 2026-07-17: 1Mentions · 2026-08-04: 3Mentions · 2026-09-07: 1PoC Mentioned / Linked · 2026-02-06: 1PoC Mentioned / Linked · 2026-05-06: 1PoC Mentioned / Linked · 2026-05-10: 1PoC Mentioned / Linked · 2026-05-11: 1PoC Mentioned / Linked · 2026-05-13: 1PoC Mentioned / Linked · 2026-09-07: 1Active Exploitation · 2026-05-22: 1Patch / Workaround · 2026-02-06: 1Patch / Workaround · 2026-02-07: 2Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-05-10: 2Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-12: 1Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-25: 2Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-05-31: 1Patch / Workaround · 2026-06-07: 2Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-06-21: 1Technical Details · 2026-02-06: 4Technical Details · 2026-02-07: 2Technical Details · 2026-02-10: 1Technical Details · 2026-03-18: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-08: 1Technical Details · 2026-05-10: 6Technical Details · 2026-05-11: 2Technical Details · 2026-05-12: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-17: 2Technical Details · 2026-05-18: 1Technical Details · 2026-05-21: 1Technical Details · 2026-05-22: 2Technical Details · 2026-05-24: 1Technical Details · 2026-05-25: 3Technical Details · 2026-05-27: 1Technical Details · 2026-05-28: 1Technical Details · 2026-05-31: 1Technical Details · 2026-06-07: 1Technical Details · 2026-06-10: 1Technical Details · 2026-06-17: 1Technical Details · 2026-06-19: 1Technical Details · 2026-06-21: 3Technical Details · 2026-06-25: 1Technical Details · 2026-06-27: 1Technical Details · 2026-07-17: 1Technical Details · 2026-08-04: 3Technical Details · 2026-09-07: 102-0602-1105-0805-1205-1705-2205-2706-0706-1906-2508-0409-07
Signal classification6 categories
Disclosure
3154.4%
Patch
1424.6%
General
915.8%
Exploit
11.8%
PoC
11.8%
Active Exploitation
11.8%
Referenced assets22 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-064
Disclosure3Patch1
2026-02-072
Patch2
2026-02-101
Disclosure1
2026-02-111
Disclosure1
2026-03-181
Disclosure1
2026-05-061
Exploit1
2026-05-081
Disclosure1
2026-05-106
Disclosure3General1Patch2
2026-05-112
Disclosure1PoC1
2026-05-121
Patch1
2026-05-131
Patch1
2026-05-161
General1
2026-05-173
Disclosure2General1
2026-05-181
General1
2026-05-211
Disclosure1
2026-05-222
Active Exploitation1General1
2026-05-241
Disclosure1
2026-05-253
Disclosure1Patch2
2026-05-271
Patch1
2026-05-281
Disclosure1
2026-05-311
Patch1
2026-06-072
Patch2
2026-06-101
Disclosure1
2026-06-171
Patch1
2026-06-193
Disclosure2General1
2026-06-213
Disclosure3
2026-06-241
General1
2026-06-251
Disclosure1
2026-06-274
Disclosure2General2
2026-07-171
Disclosure1
2026-08-043
Disclosure3
2026-09-071
Disclosure1
Full discourse20 posts
  • Cypher@cypher_hyd
    Disclosure

    Why AI agent security becomes mandatory by the end of 2026 CVE-2026-25592 and CVE-2026-26030 Two confirmed RCEs in Semantic Kernel (SK). One prompt escalates to host-level code execution. SK is a widely deployed agent framework. If you build on it, audit tool-call permissions now. DryRun Security study: 26 of 30 agent pull requests introduced a real vulnerability. Broken access control appeared in every model tested. Claude Code, OpenAI Codex, Gemini — all of them. Shipping agent-generated code without inline scanning introduces a near-certain vulnerability. OWASP Top 10 for Agentic Applications First peer-reviewed taxonomy for agentic risk. Covers goal hijacking, tool misuse, identity abuse, and memory poisoning. Enterprise buyers will require this checklist. Architects should already be mapping to it. HashiCorp on why legacy identity and access management (IAM) breaks for agents - Agents have no login, no static role, no human session. They invoke other agents dynamically. 97% of orgs that had an AI security incident lacked dedicated AI access controls. Human-centric IAM does not port. Gravitee survey: 52% of production agents run with zero security monitoring - Only 14.4% of orgs have full IT or security approval for their agent fleet. Most deployed agents are invisible to the security team. That is not a gap. That is an open door. IBM's Agent-to-Agent Security (A2AS) framework Behaviour certificates, authenticated prompts, and defined security boundaries. IBM is positioning A2AS as the HTTPS equivalent for an agentic runtime. If it gets traction, it becomes a compliance floor. Track it.

    Post summary

    The post discloses two confirmed RCE CVEs (CVE‑2026‑25592 and CVE‑2026‑26030) in Semantic Kernel, emphasizing the need for immediate security audits of AI agent deployments.

    31020185
    178 followersView on X
  • The Crypto Illuminati@0x_illuminati
    Disclosure

    A prompt can be a shell now. Microsoft just disclosed 2 Semantic Kernel agent bugs that can turn prompt injection into real compromise: 1) CVE-2026-26030: prompt injection → host RCE via In‑Memory Vector Store Search Plugin (default config) 2) CVE-2026-25592: arbitrary file write → full RCE (Windows Startup folder) If your agent can browse + run tools + persist memory… what’s your blast radius?

    Post summary

    Microsoft disclosed two Semantic Kernel agent bugs that enable prompt injection to lead to host remote code execution and arbitrary file writes culminating in full RCE, with detailed technical information but no PoC, exploit code, patch, or active exploitation report.

    10022151
    14.1K followersView on X
  • SciPHR@sciphr_
    Disclosure

    Microsoft Semantic Kernel's prompt-injection-to-RCE vulnerabilities. On May 7, Microsoft disclosed two critical bugs in Semantic Kernel, its framework for building AI agents. CVE-2026-26030 (CVSS 9.8) in the Python SDK and CVE-2026-25592 (CVSS 10.0) in the .NET SDK both turn a single crafted prompt into host-level code execution. The Python bug routed attacker-controlled vector store fields straight into eval(). The .NET bug exposed an internal file download helper as a callable kernel function with no path validation, letting a prompt-injected agent escape its sandbox by abusing DownloadFileAsync. The mechanism in both cases is the same. Functions intended for the application were registered with the LLM as tools it could call directly. Once a prompt convinced the model to call them with the wrong arguments, the model executed them with whatever privileges the application had. Prompt injection is often treated as a content problem, something to be filtered or rephrased. Once an LLM is wired to tools that touch the filesystem, the network, or a code interpreter, the prompt carries the privileges of whatever you registered. The tool registry is the attack surface. What lives in it, and how tightly its arguments are validated, decides what a successful injection can actually do. Source: https://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/

    Post summary

    Microsoft discloses two critical CVEs (CVE‑2026‑26030 and CVE‑2026‑25592) in Semantic Kernel, describing high‑severity prompt‑injection–to‑RCE mechanisms via eval() and unvalidated file downloads, but no PoC, exploit code, active exploitation, or patch information is provided.

    0202098
    53 followersView on X
  • Kwame@kwame_nyx
    Disclosure

    @Microsoft disclosed CVE-2026-25592 and CVE-2026-26030 on May 7. Both turn prompt injection in Semantic Kernel into arbitrary file writes, RCE in the agent host. The root cause wasn't model behavior. It was a callable kernel function (DownloadFileAsync) accidentally exposed to the agent with no path validation. Agent identity isn't just "who is this agent." It's "what tools is this identity allowed to call, with what parameters." If your audit log can't answer that, you can't investigate the next one of these.

    Post summary

    Microsoft disclosed two CVEs (CVE-2026-25592 and CVE-2026-26030) affecting Semantic Kernel that enable prompt injection to arbitrarily write files and achieve remote code execution due to an exposed kernel function lacking path validation.

    1003061
    67 followersView on X
  • dbugs@ptdbugs
    Exploit

    🔒 Bypassing the CVE-2026-25592 Patch in Microsoft Semantic Kernel PT ID: PT-2026-6792 The research describes a vulnerability in Microsoft Semantic Kernel (.NET SDK v1.47.0–1.48.0) and Agent Framework 1.0 that enables remote code execution (RCE). The issue stems from an unsafe trust model in which stochastic LLM output is interpreted as executable system commands. The vulnerability forms a chain of CWE-1039 → CWE-22 → CWE-94 and remains exploitable despite the official patch for CVE-2026-25592 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-25592). Exploitation requires no privileges, can be performed remotely, and may result in overwriting the host application's source code (the “Self-Nuke” vector). The research demonstrates six independent 0-day bypasses of the implemented security mechanisms. 📎 Article: https://nuka-ai.github.io/posts/2026-07-28-Semantic-Kernel-disclosure/ #dbugs_attacks

    Post summary

    The post discloses that Microsoft Semantic Kernel remains vulnerable to CVE-2026-25592, presenting six bypass techniques that enable remote code execution even after the official patch, and links to a detailed research article and vendor advisory.

    00022267
    1.0K followersView on X
  • Cyphrex@Cyphrexio
    Disclosure

    CVE-2026-25592 and CVE-2026-26030. @Microsoft Semantic Kernel. Both vulnerabilities allow prompt injection to escalate to host-level remote code execution. A crafted prompt reaches the agent, the agent processes it through Semantic Kernel, and the attacker gains code execution on the host machine. Semantic Kernel is one of the most widely deployed enterprise agent frameworks. The vulnerabilities are in the framework itself, not in any specific model. The attack surface is the execution environment. Behavioral enforcement that validates tool calls before they execute stops the escalation before the host is compromised. http://cyphrex.io #AIAgents #AISecurity #AgenticAI #LLMagents

    Post summary

    The post announces two new CVEs (CVE‑2026‑25592 and 26030) that allow prompt injection in Microsoft Semantic Kernel to achieve host‑level remote code execution, presenting technical details but no PoC, exploit tool, or patch information.

    3000097
    61 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: Most "AI agents" are just prompts duct-taped to APIs. Microsoft's Semantic Kernel AI agent framework shipped two critical vulnerabilities — CVE-2026-25592 and CVE-2026-26030 — that let an attacker convert a single malicious prompt into host-level…

    Post summary

    The post announces that Microsoft’s Semantic Kernel AI agent framework contains two critical CVEs that allow an attacker to achieve host‑level execution through a single malicious prompt.

    2000059
    297 followersView on X
  • The Crypto Illuminati@0x_illuminati
    Disclosure

    Prompt injection just graduated from “annoying” to “remote shell.” Microsoft disclosed 2 critical bugs in its Semantic Kernel agent framework (May 7, 2026): 1) CVE-2026-25592 — a mis-tagged tool let an agent be tricked into writing a file anywhere (e.g., Windows Startup) → code execution on reboot. 2) CVE-2026-26030 — an InMemoryVectorStore filter used eval() on attacker-controlled data → RCE. If your agent can auto-invoke tools… your threat model is now “untrusted text == code.” What’s the first tool you’d remove from an agent in production: file-write, shell, or browser?

    Post summary

    Microsoft disclosed two critical CVEs in its Semantic Kernel agent framework, describing how CVE‑2026‑25592 allows arbitrary file writes for code execution on reboot and CVE‑2026‑26030 enables RCE via eval() on attacker‑controlled data, but no PoC, exploit, or patch is provided.

    00020144
    14.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25592 - Critical Semantic Kernel is an SDK used to build, orchestrate, and deploy AI agents and multi-agent systems. Prior to 1.70.0, an Arbitrary File Write vulnerability has been identified in Microsoft... https://www.thehackerwire.com/vulnerability/CVE-2026-25592/ https://t.co/Mgo6yCmWir

    Post summary

    CVE-2026-25592 is an arbitrary file write vulnerability in Semantic Kernel (versions before 1.70.0), marked as critical; the text provides vulnerability details but does not mention PoC, exploit code, active exploitation, or patch information.

    10100162
    113 followersView on X
  • LiveOverflow 🔴@LiveOverflow
    Disclosure

    @Deep_Star_Six Are you rage-baiting? First google result: https://particula.tech/blog/semantic-kernel-cve-2026-25592-prompt-injection-rce https://t.co/9402S4slMr

    Post summary

    The tweet directs to a blog entry outlining CVE‑2026‑25592, a prompt‑injection flaw that enables remote code execution in Semantic Kernel, without referencing active attacks or fixes.

    10000405
    163.8K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    What this means for your agents and systems: When Prompts Become Shells: CVE-2026-25592 & CVE-2026-26030 Prove AI Agent Frameworks Are the New OS — And They Have Root Bugs

    Post summary

    The headline indicates that CVE-2026-25592 and CVE-2026-26030 contain root bugs in AI agent frameworks, but it provides no technical, patch, or exploitation details.

    1000031
    296 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-25592 · < 1.39.4 → < 1.71.0 When Prompts Become Shells: CVE-2026-25592 & CVE-2026-26030 Prove AI Agent Frameworks Are the New OS — And They Have Root Bugs

    Post summary

    The post discloses new CVEs affecting AI agent frameworks, specifying affected version ranges and root access implications, but does not provide PoC, exploit code, or patch information.

    1000042
    296 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    When Prompts Become Shells: CVE-2026-25592 & CVE-2026-26030 Prove AI Agent Frameworks Are the New OS — And They Have Root Bugs Microsoft disclosed two Critical CVSS 9.9 vulnerabilities in Semantic Kernel — its open-source AI agent framework with 27,000+ GitHub stars — on…

    Post summary

    Microsoft announced two critical CVSS 9.9 vulnerabilities in the Semantic Kernel AI framework, but no PoC, exploitation details, patches, or mitigating information are provided.

    1000038
    296 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    When Prompts Become Shells: CVE-2026-25592 & CVE-2026-26030 and the New Attack Surface Every AI Team Is Missing. ---

    Post summary

    The text simply names CVE-2026-25592 and CVE-2026-26030 without providing details on exploitation, patches, or technical aspects.

    1000059
    295 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-25592 AI agent frameworks (Anthropic's MCP, Microsoft's Semantic Kernel, CrewAI, LangChain) have become critical infrastructure—but they're shipping with architectural flaws that turn prompts into shells and dependencies into backdoors.

    Post summary

    The announcement highlights CVE‑2026‑25592, noting that several AI agent frameworks contain architectural flaws that can turn prompts into shells and dependencies into backdoors.

    1000058
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Semantic Kernel RCE vulnerabilities documented this week (CVE-2026-25592, CVE-2026-26030) illustrate the severity: a malicious prompt or tool configuration can pivot from model interaction to OS-level command execution. Organizations deploying AI agents at scale…

    Post summary

    A recent disclosure of two RCE vulnerabilities in Semantic Kernel (CVE-2026-25592, CVE-2026-26030) highlights that malicious prompts or tool misconfigurations can lead to OS‑level command execution.

    1000033
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    150 million · CVE-2026-25592 · < 1.71.0 → 1.71.0 When the Framework Is the Vulnerability: Semantic Kernel RCE, MCP's Architectural Flaw, and the Collapse of the AI Agent Trust Boundary

    Post summary

    CVE-2026-25592 is a remote code execution flaw in Semantic Kernel affecting versions below 1.71.0; it is mitigated by upgrading to 1.71.0. No evidence of active exploitation, PoC, or false positive is provided.

    1000043
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    In the last 72 hours, researchers have disclosed critical vulnerabilities in three major agentic frameworks: CVE-2026-25592 & CVE-2026-26030 (Semantic Kernel): Prompt injection RCE CVE-2026-42302 (FastGPT): Agent runtime sandbox escape CVE-2026-44895 (GitLab MCP Server):…

    Post summary

    Researchers have announced critical RCE and sandbox escape vulnerabilities across three major frameworks, focusing on disclosure of the new findings.

    1000050
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE-2026-25592 TL;DR Agentic AI frameworks (LangChain, CrewAI, AutoGen, Semantic Kernel) have become invisible to traditional endpoint security. Your EDR logs API calls, file access, and network traffic—but not the prompts that trigger

    Post summary

    The post notes that agentic AI frameworks evade traditional endpoint detection, but provides no concrete proof‑of‑concept, exploit code, or mitigation details for CVE‑2026‑25592.

    1000086
    294 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Audit Lag: Why Your Agentic Framework Security Posture Is 90 Days Behind Over the past six weeks, Lyrie's research has documented 17 critical vulnerabilities in agentic frameworks CVE-2026-42208, CVE-2026-44843, CVE-2026-25592, CVE-2026-26030, etc..

    Post summary

    Lyrie’s research lists 17 critical vulnerabilities in agentic frameworks with several CVE identifiers, but it lacks specific technical details, exploit code, or mitigation information.

    1000039
    294 followersView on X

Explore more