CVE-2026-70337Disclosure(microsoft / powershell)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft powershell systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • powershell

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-08-25); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
powershell

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-11: 1Mentions · 2026-08-25: 2Mentions · 2026-09-11: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-08-11: 1Technical Details · 2026-08-25: 2Technical Details · 2026-09-11: 108-1108-2509-11
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-111
Disclosure1
2026-08-252
Disclosure1Patch1
2026-09-111
Disclosure1
Full discourse4 posts
  • Andy@TheTeaToast
    Disclosure

    Just got a new 0-day CVE assigned: another PowerShell 1-click RCE Missed the mail and only found out about it late. CVE-2026-70337 https://t.co/tjeSBjT1nj

    Post summary

    The author announces a newly assigned zero‑day CVE, CVE‑2026‑70337, describing it as a PowerShell 1‑click remote code execution flaw, but provides no PoC, exploitation details, or patches.

    61901756016.5K
    1.1K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Patch

    🔴 @theteatoast tarafından bildirilen CVE-2026-70337 (Microsoft PowerShell Core'daki Relative Path Traversal tabanlı 1-click RCE açığı) ağustos güncellemeleriyle yamalandı. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70337

    Post summary

    The post announces that CVE‑2026‑70337, a 1‑click RCE in PowerShell Core triggered by relative path traversal, has been mitigated in August updates, with Microsoft supplying an update guide.

    03082839
    2.4K followersView on X
  • HASAN FLAYYIH ABDULLAH@hasanfleyah
    Disclosure

    I discovered CVE-2026-70337, an arbitrary file write vulnerability in PowerShell Invoke-WebRequest. A malicious server can abuse an HTTP redirect with a URL-encoded path traversal sequence, causing -OutFile to write the downloaded file outside the intended directory. https://t.co/iwmikYkhWw

    Post summary

    The tweet announces a newly discovered CVE-2026-70337, detailing an arbitrary file write defect in PowerShell’s Invoke-WebRequest that can be triggered via malicious redirects and encoded path traversal, but it provides no PoC, exploit code, active exploitation, patch information, or false positive claim.

    0002076
    122 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-70337 Relative Path Traversal in Microsoft PowerShell Core Enables Network Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-70337

    Post summary

    The text announces CVE-2026-70337, a relative path traversal flaw in Microsoft PowerShell Core that could enable network code execution, but provides no PoC, exploit, or patch details.

    00000104
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftpowershell---

Explore more