CVE-2026-26030Disclosure(microsoft / semantic_kernel)

CRITICALCVSS 9.9 · CRITICAL

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch microsoft semantic_kernel systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The problem has been fixed in version `python-1.39.4`. Users should upgrade this version or higher. As a workaround, avoid using `InMemoryVectorStore` for production scenarios.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • semantic_kernel

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 84 mentions across 44 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 39 signals
  • Technical details provided in 69 signals
  • Disclosure: 40 classified signals
  • General: 6 classified signals
  • Peaked 42d ago at 5 mentions (2026-02-20); latest day: 3
  • 84 total mentions across 44 days

Affected systems

Vendors
Products
semantic_kernel

Deep dive

Activity timeline84 mentions / 44d
01345Mentions · 2026-02-19: 3Mentions · 2026-02-20: 5Mentions · 2026-02-24: 5Mentions · 2026-03-05: 2Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-12: 1Mentions · 2026-03-16: 1Mentions · 2026-03-20: 1Mentions · 2026-03-25: 3Mentions · 2026-03-27: 1Mentions · 2026-03-29: 1Mentions · 2026-03-30: 1Mentions · 2026-05-08: 2Mentions · 2026-05-09: 1Mentions · 2026-05-10: 5Mentions · 2026-05-11: 2Mentions · 2026-05-12: 3Mentions · 2026-05-13: 1Mentions · 2026-05-14: 1Mentions · 2026-05-15: 1Mentions · 2026-05-16: 2Mentions · 2026-05-17: 2Mentions · 2026-05-18: 3Mentions · 2026-05-19: 1Mentions · 2026-05-21: 1Mentions · 2026-05-24: 1Mentions · 2026-05-25: 3Mentions · 2026-05-27: 1Mentions · 2026-05-28: 1Mentions · 2026-05-31: 1Mentions · 2026-06-07: 2Mentions · 2026-06-10: 2Mentions · 2026-06-11: 1Mentions · 2026-06-13: 2Mentions · 2026-06-19: 2Mentions · 2026-06-21: 3Mentions · 2026-06-22: 1Mentions · 2026-06-24: 3Mentions · 2026-06-25: 1Mentions · 2026-06-27: 4Mentions · 2026-07-01: 1Mentions · 2026-07-17: 1Mentions · 2026-08-04: 3PoC Mentioned / Linked · 2026-05-10: 2PoC Mentioned / Linked · 2026-05-13: 1PoC Mentioned / Linked · 2026-05-15: 1PoC Mentioned / Linked · 2026-06-13: 1PoC Mentioned / Linked · 2026-06-22: 1Exploit Tool / Code · 2026-05-10: 1Exploit Tool / Code · 2026-05-19: 1Exploit Tool / Code · 2026-06-22: 1Active Exploitation · 2026-05-08: 1Active Exploitation · 2026-05-09: 1Active Exploitation · 2026-06-10: 1Active Exploitation · 2026-08-04: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-20: 3Patch / Workaround · 2026-02-24: 2Patch / Workaround · 2026-03-05: 2Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-03-25: 3Patch / Workaround · 2026-03-29: 1Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-05-10: 3Patch / Workaround · 2026-05-11: 1Patch / Workaround · 2026-05-12: 3Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-05-16: 1Patch / Workaround · 2026-05-18: 3Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-05-25: 2Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-05-31: 1Patch / Workaround · 2026-06-07: 2Patch / Workaround · 2026-06-11: 1Patch / Workaround · 2026-06-13: 1Patch / Workaround · 2026-06-22: 1Patch / Workaround · 2026-07-17: 1Technical Details · 2026-02-19: 3Technical Details · 2026-02-20: 4Technical Details · 2026-02-24: 3Technical Details · 2026-03-05: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-25: 2Technical Details · 2026-03-27: 1Technical Details · 2026-03-29: 1Technical Details · 2026-03-30: 1Technical Details · 2026-05-08: 2Technical Details · 2026-05-09: 1Technical Details · 2026-05-10: 5Technical Details · 2026-05-11: 2Technical Details · 2026-05-12: 3Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-15: 1Technical Details · 2026-05-16: 2Technical Details · 2026-05-17: 2Technical Details · 2026-05-18: 3Technical Details · 2026-05-19: 1Technical Details · 2026-05-21: 1Technical Details · 2026-05-24: 1Technical Details · 2026-05-25: 3Technical Details · 2026-05-27: 1Technical Details · 2026-05-28: 1Technical Details · 2026-05-31: 1Technical Details · 2026-06-07: 1Technical Details · 2026-06-10: 1Technical Details · 2026-06-11: 1Technical Details · 2026-06-13: 2Technical Details · 2026-06-19: 1Technical Details · 2026-06-21: 3Technical Details · 2026-06-22: 1Technical Details · 2026-06-25: 1Technical Details · 2026-06-27: 2Technical Details · 2026-07-01: 1Technical Details · 2026-07-17: 1Technical Details · 2026-08-04: 202-1903-1003-2003-3005-1105-1505-1905-2706-1006-2106-2708-04
Signal classification6 categories
Disclosure
4047.6%
Patch
2833.3%
General
67.1%
Active Exploitation
44.8%
PoC
44.8%
Exploit
22.4%
Referenced assets28 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-193
Disclosure2Patch1
2026-02-205
Disclosure2Patch3
2026-02-245
Disclosure3General1Patch1
2026-03-052
Patch2
2026-03-101
Patch1
2026-03-111
Disclosure1
2026-03-121
Disclosure1
2026-03-161
Disclosure1
2026-03-201
Patch1
2026-03-253
Patch3
2026-03-271
Disclosure1
2026-03-291
Patch1
2026-03-301
Disclosure1
2026-05-082
Active Exploitation1Disclosure1
2026-05-091
Active Exploitation1
2026-05-105
Disclosure1Patch2PoC2
2026-05-112
Disclosure1Exploit1
2026-05-123
Patch3
2026-05-131
Patch1
2026-05-141
Disclosure1
2026-05-151
Patch1
2026-05-162
Disclosure1Patch1
2026-05-172
Disclosure2
2026-05-183
Patch3
2026-05-191
Exploit1
2026-05-211
Disclosure1
2026-05-241
Disclosure1
2026-05-253
Disclosure2Patch1
2026-05-271
Disclosure1
2026-05-281
Disclosure1
2026-05-311
Patch1
2026-06-072
Disclosure1Patch1
2026-06-102
Active Exploitation1Disclosure1
2026-06-111
Disclosure1
2026-06-132
Patch1PoC1
2026-06-192
Disclosure1General1
2026-06-213
Disclosure3
2026-06-221
PoC1
2026-06-243
General3
2026-06-251
Disclosure1
2026-06-274
Disclosure3General1
2026-07-011
Disclosure1
2026-07-171
Disclosure1
2026-08-043
Active Exploitation1Disclosure2
Full discourse20 posts
  • Sami Laiho@samilaiho
    Patch

    Improper Control of Generation of Code ('Code Injection') in microsoft semantic-kernel URL: https://nvd.nist.gov/vuln/detail/CVE-2026-26030 Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.9

    Post summary

    CVE-2026-26030 is a critical code‑injection flaw in microsoft semantic‑kernel with an official fix available.

    01060435
    30.4K followersView on X
  • dbugs@ptdbugs
    PoC

    🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-26030 PT ID: PT-2026-20868 Vendor: Microsoft Product: Semantic-Kernel Description: Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the "InMemoryVectorStore" filter functionality. The problem has been fixed in version "python-1.39.4". Users should upgrade this version or higher. As a workaround, avoid using "InMemoryVectorStore" for production scenarios. Link: https://github.com/InertFluid/sk-cve-2026-26030-lab #dbugs_vuln

    Post summary

    A PoC/exploit for CVE‑2026‑26030 has been released, demonstrating remote code execution in Semantic Kernel via the InMemoryVectorStore filter; the vendor has issued a patch in version 1.39.4, and users are advised to upgrade or avoid the affected component.

    01041504
    3.0K followersView on X
  • Cypher@cypher_hyd
    Disclosure

    Why AI agent security becomes mandatory by the end of 2026 CVE-2026-25592 and CVE-2026-26030 Two confirmed RCEs in Semantic Kernel (SK). One prompt escalates to host-level code execution. SK is a widely deployed agent framework. If you build on it, audit tool-call permissions now. DryRun Security study: 26 of 30 agent pull requests introduced a real vulnerability. Broken access control appeared in every model tested. Claude Code, OpenAI Codex, Gemini — all of them. Shipping agent-generated code without inline scanning introduces a near-certain vulnerability. OWASP Top 10 for Agentic Applications First peer-reviewed taxonomy for agentic risk. Covers goal hijacking, tool misuse, identity abuse, and memory poisoning. Enterprise buyers will require this checklist. Architects should already be mapping to it. HashiCorp on why legacy identity and access management (IAM) breaks for agents - Agents have no login, no static role, no human session. They invoke other agents dynamically. 97% of orgs that had an AI security incident lacked dedicated AI access controls. Human-centric IAM does not port. Gravitee survey: 52% of production agents run with zero security monitoring - Only 14.4% of orgs have full IT or security approval for their agent fleet. Most deployed agents are invisible to the security team. That is not a gap. That is an open door. IBM's Agent-to-Agent Security (A2AS) framework Behaviour certificates, authenticated prompts, and defined security boundaries. IBM is positioning A2AS as the HTTPS equivalent for an agentic runtime. If it gets traction, it becomes a compliance floor. Track it.

    Post summary

    The text announces two confirmed RCE CVEs in Semantic Kernel (CVE‑2026‑25592 and CVE‑2026‑26030), providing technical details but no PoC, exploit code, active exploitation evidence, or patch information.

    31020185
    178 followersView on X
  • Dan D. Aridor دان اريدور@daridor
    Patch

    4/ Timeline: Dec 1, 2025 — reported to MSRC (Case 104081, VULN-167388) Jan 2, 2026 — MSRC requested engineering update Jan 24, 2026 — MSRC: "We confirmed the behavior you reported." Feb 19, 2026 — CVE-2026-26030 published (CVSS 10.0, Scope: Changed) Feb 19, 2026 — Patch shipped in PR #13505 80 days from submission to CVE publication.

    Post summary

    CVE-2026-26030 was reported to MSRC, confirmed, published with a CVSS 10.0 score, and a patch was released promptly in PR #13505.

    1005099
    8.6K followersView on X
  • The Crypto Illuminati@0x_illuminati
    Disclosure

    A prompt can be a shell now. Microsoft just disclosed 2 Semantic Kernel agent bugs that can turn prompt injection into real compromise: 1) CVE-2026-26030: prompt injection → host RCE via In‑Memory Vector Store Search Plugin (default config) 2) CVE-2026-25592: arbitrary file write → full RCE (Windows Startup folder) If your agent can browse + run tools + persist memory… what’s your blast radius?

    Post summary

    Microsoft has disclosed two Semantic Kernel agent vulnerabilities that allow host remote code execution via prompt injection and arbitrary file write, but no PoC, exploit code, or patch information is provided.

    10022151
    14.1K followersView on X
  • Dan D. Aridor دان اريدور@daridor
    Patch

    10/ Full disclosure: CVE-2026-26030 GHSA-xjw9-4gw8-4rqx Patch: PR #13505 (Semantic Kernel python-1.39.4) Responsible disclosure followed throughout. Patch is live before this post. Full technical writeup available on request.

    Post summary

    The post announces that CVE-2026-26030 has been patched (PR #13505 for Semantic Kernel python-1.39.4) and the patch is already live; no PoC, exploit, or active exploitation information is provided.

    10040111
    8.6K followersView on X
  • SciPHR@sciphr_
    Disclosure

    Microsoft Semantic Kernel's prompt-injection-to-RCE vulnerabilities. On May 7, Microsoft disclosed two critical bugs in Semantic Kernel, its framework for building AI agents. CVE-2026-26030 (CVSS 9.8) in the Python SDK and CVE-2026-25592 (CVSS 10.0) in the .NET SDK both turn a single crafted prompt into host-level code execution. The Python bug routed attacker-controlled vector store fields straight into eval(). The .NET bug exposed an internal file download helper as a callable kernel function with no path validation, letting a prompt-injected agent escape its sandbox by abusing DownloadFileAsync. The mechanism in both cases is the same. Functions intended for the application were registered with the LLM as tools it could call directly. Once a prompt convinced the model to call them with the wrong arguments, the model executed them with whatever privileges the application had. Prompt injection is often treated as a content problem, something to be filtered or rephrased. Once an LLM is wired to tools that touch the filesystem, the network, or a code interpreter, the prompt carries the privileges of whatever you registered. The tool registry is the attack surface. What lives in it, and how tightly its arguments are validated, decides what a successful injection can actually do. Source: https://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/

    Post summary

    Microsoft has disclosed two critical prompt‑injection-to‑RCE bugs in Semantic Kernel, detailing how crafted prompts can execute host‑level code via eval() in the Python SDK and an unvalidated file download in the .NET SDK, but no PoC, exploit tools, patches, or evidence of active exploitation is provided.

    0202098
    53 followersView on X
  • Kwame@kwame_nyx
    Disclosure

    @Microsoft disclosed CVE-2026-25592 and CVE-2026-26030 on May 7. Both turn prompt injection in Semantic Kernel into arbitrary file writes, RCE in the agent host. The root cause wasn't model behavior. It was a callable kernel function (DownloadFileAsync) accidentally exposed to the agent with no path validation. Agent identity isn't just "who is this agent." It's "what tools is this identity allowed to call, with what parameters." If your audit log can't answer that, you can't investigate the next one of these.

    Post summary

    Microsoft disclosed CVE‑2026‑25592 and CVE‑2026‑26030 as prompt injection flaws in Semantic Kernel that allow arbitrary file writes and remote code execution via an exposed kernel function without path validation.

    1003061
    67 followersView on X
  • Cyphrex@Cyphrexio
    Disclosure

    CVE-2026-25592 and CVE-2026-26030. @Microsoft Semantic Kernel. Both vulnerabilities allow prompt injection to escalate to host-level remote code execution. A crafted prompt reaches the agent, the agent processes it through Semantic Kernel, and the attacker gains code execution on the host machine. Semantic Kernel is one of the most widely deployed enterprise agent frameworks. The vulnerabilities are in the framework itself, not in any specific model. The attack surface is the execution environment. Behavioral enforcement that validates tool calls before they execute stops the escalation before the host is compromised. http://cyphrex.io #AIAgents #AISecurity #AgenticAI #LLMagents

    Post summary

    The post discloses two CVEs in Microsoft Semantic Kernel that allow prompt injection leading to host‑level RCE, and notes a mitigative enforcement strategy.

    3000097
    61 followersView on X
  • Bradley Cassada@bcassada
    Disclosure

    Prompt-to-RCE: when an agent can run code, a prompt injection becomes remote code execution. CVE-2026-26030 turned one crafted prompt into a shell. It can execute... whats the defense? https://www.microsoft.com/en-us/security/blog/2026/05/07/prompts-become-shells-rce-vulnerabilities-ai-agent-frameworks/ #AISecurity #PromptInjection #LLMSecurity

    Post summary

    The post announces CVE-2026-26030 as a prompt‑to‑shell remote code execution flaw, cites a Microsoft security blog, but does not provide exploit code, active exploitation evidence, or patch information.

    1002041
    245 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: Most "AI agents" are just prompts duct-taped to APIs. Microsoft's Semantic Kernel AI agent framework shipped two critical vulnerabilities — CVE-2026-25592 and CVE-2026-26030 — that let an attacker convert a single malicious prompt into host-level…

    Post summary

    Microsoft’s Semantic Kernel AI agent framework is reported to contain two critical CVEs that allow an attacker to execute host‑level code through a single malicious prompt.

    2000059
    297 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/2026-05-13-15-deepdive-semantic-kernel-rce-cve-2026-26030-prompt-injection-agent-framework #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The excerpt merely references a CVE and a research URL with accompanying hashtags, providing no concrete technical or exploit-related details.

    0101030
    295 followersView on X
  • The Crypto Illuminati@0x_illuminati
    Disclosure

    Prompt injection just graduated from “annoying” to “remote shell.” Microsoft disclosed 2 critical bugs in its Semantic Kernel agent framework (May 7, 2026): 1) CVE-2026-25592 — a mis-tagged tool let an agent be tricked into writing a file anywhere (e.g., Windows Startup) → code execution on reboot. 2) CVE-2026-26030 — an InMemoryVectorStore filter used eval() on attacker-controlled data → RCE. If your agent can auto-invoke tools… your threat model is now “untrusted text == code.” What’s the first tool you’d remove from an agent in production: file-write, shell, or browser?

    Post summary

    Microsoft disclosed two critical CVEs (CVE‑2026‑25592 and CVE‑2026‑26030) in Semantic Kernel that allow code execution via file writes and RCE through eval(), highlighting a significant prompt‑injection risk.

    00020144
    14.0K followersView on X
  • RagingCISO@CisoRaging77913
    Patch

    CVE-2026-26030: Microsoft's official LLM agent framework ships with a CVE, patched quietly in Patch Tuesday. Vuln in tool orchestration—the brain of your agent. Haven't updated since March 11? Your prod is the attack surface. Scanning Python deps isn't optional anymore.

    Post summary

    Microsoft’s CVE-2026-26030, impacting its LLM agent framework, has been fixed in the latest Patch Tuesday, and users are urged to update to mitigate potential risk.

    0011078
    5 followersView on X
  • GXO株式会社@GXO20200304
    General

    あなたの会社のAIアプリ、開発環境のまま動いていませんか? Semantic KernelのInMemoryVectorStore、本番で使っていないか確認してください。 CVSS 9.9の脆弱性、今すぐチェックを。 https://gxo.co.jp/column/semantic-kernel-cve-2026-26030-ai-security #AI開発 #脆弱性対策 #情報セキュリティ https://t.co/vvc7n0Gv4T

    Post summary

    The post alerts that CVE‑2026‑26030, a CVSS 9.9 vulnerability in Semantic Kernel’s InMemoryVectorStore, may affect companies still running the AI app in a development environment, urging them to verify production usage.

    1001050
    15 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26030 Remote Code Execution in Semantic Kernel Python SDK Versions Below 1.39.4 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26030

    Post summary

    CVE‑2026‑26030 describes a Remote Code Execution vulnerability in Semantic Kernel Python SDK versions below 1.39.4, with a reference to a vulnerability detail page but no PoC, exploit, or fix details provided.

    0001167
    4.0K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Microsoft disclosed two Critical (CVSS 9.9) vulnerabilities in Semantic Kernel — its open-source AI agent framework with 27,000+ GitHub stars — on May 7, 2026. CVE-2026-26030 chains prompt injection through an eval()-backed vector store filter into host-level remote code…

    Post summary

    Microsoft disclosed two Critical CVE‑2026‑26030 vulnerabilities in Semantic Kernel, highlighting a prompt injection chain through an eval‑backed vector store that allows host‑level remote code execution.

    1000035
    296 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    What this means for your agents and systems: When Prompts Become Shells: CVE-2026-25592 & CVE-2026-26030 Prove AI Agent Frameworks Are the New OS — And They Have Root Bugs

    Post summary

    The excerpt lists two CVE identifiers linked to AI agent framework vulnerabilities but supplies no further technical or operational details.

    1000031
    296 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-25592 · < 1.39.4 → < 1.71.0 When Prompts Become Shells: CVE-2026-25592 & CVE-2026-26030 Prove AI Agent Frameworks Are the New OS — And They Have Root Bugs

    Post summary

    The brief headline announces that CVE-2026-25592 (and CVE-2026-26030) affect AI Agent Framework versions below 1.71.0, indicating root bugs but providing no technical, exploit, or remediation details.

    1000042
    296 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    When Prompts Become Shells: CVE-2026-25592 & CVE-2026-26030 Prove AI Agent Frameworks Are the New OS — And They Have Root Bugs Microsoft disclosed two Critical CVSS 9.9 vulnerabilities in Semantic Kernel — its open-source AI agent framework with 27,000+ GitHub stars — on…

    Post summary

    Microsoft disclosed two critical vulnerabilities (CVE‑2026‑25592 and CVE‑2026‑26030) in the Semantic Kernel AI agent framework, noting CVSS 9.9 scores and emphasizing a serious security flaw.

    1000038
    296 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftsemantic_kernel-python-

Explore more