Sami Laiho[verified]@samilaihoPatch
CVE-2026-26030 is a critical code‑injection flaw in microsoft semantic‑kernel with an official fix available.
dbugs[verified]@ptdbugsPoC
A PoC/exploit for CVE‑2026‑26030 has been released, demonstrating remote code execution in Semantic Kernel via the InMemoryVectorStore filter; the vendor has issued a patch in version 1.39.4, and users are advised to upgrade or avoid the affected component.
Cypher[verified]@cypher_hydDisclosure
The text announces two confirmed RCE CVEs in Semantic Kernel (CVE‑2026‑25592 and CVE‑2026‑26030), providing technical details but no PoC, exploit code, active exploitation evidence, or patch information.
Dan D. Aridor دان اريدور[verified]@daridorPatch
CVE-2026-26030 was reported to MSRC, confirmed, published with a CVSS 10.0 score, and a patch was released promptly in PR #13505.
The Crypto Illuminati[verified]@0x_illuminatiDisclosure
Microsoft has disclosed two Semantic Kernel agent vulnerabilities that allow host remote code execution via prompt injection and arbitrary file write, but no PoC, exploit code, or patch information is provided.
Dan D. Aridor دان اريدور[verified]@daridorPatch
The post announces that CVE-2026-26030 has been patched (PR #13505 for Semantic Kernel python-1.39.4) and the patch is already live; no PoC, exploit, or active exploitation information is provided.
SciPHR[verified]@sciphr_Disclosure
Microsoft has disclosed two critical prompt‑injection-to‑RCE bugs in Semantic Kernel, detailing how crafted prompts can execute host‑level code via eval() in the Python SDK and an unvalidated file download in the .NET SDK, but no PoC, exploit tools, patches, or evidence of active exploitation is provided.
Cyphrex[verified]@CyphrexioDisclosure
The post discloses two CVEs in Microsoft Semantic Kernel that allow prompt injection leading to host‑level RCE, and notes a mitigative enforcement strategy.