CVE-2026-59119Disclosure(microsoft / powershell)

LOWCVSS 7.3 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft powershell systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Incorrect default permissions in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-276

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • powershell

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
powershell

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-25: 1PoC Mentioned / Linked · 2026-08-25: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-08-25: 108-25
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CyStack@CyStackSecurity
    Disclosure

    CVE-2026-59119: Privilege escalation flaw in Microsoft PowerShell, the command-line tool installed by default on most Windows systems. Overly broad default permissions on an internal operation. An attacker with a local foothold, even at low privilege, exploits it to gain SYSTEM. Patched in v7.4.19, v7.5.10, v7.6.5. Found by a CyStack researcher. Details at https://cystack.net/disclosures #CyStack #CyberSecurity #Vulnerability #Microsoft #PowerShell #PrivilegeEscalation #InfoSec

    Post summary

    The post discloses a local privilege escalation issue in Microsoft PowerShell, lists patches for affected versions, and provides a link to additional details, but does not confirm active exploitation or provide a PoC.

    0000090
    3.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftpowershell---

Explore more