Microsoft Security disclosed on May 8, 2026 two critical remote code execution vulnerabilities in Microsoft Semantic Kernel, an open-source AI agent framework with over 27,000 GitHub stars. CVE-2026-25592 and CVE-2026-26030 allowed attackers to achieve unauthorized code execution through prompt injection attacks exploiting the framework's In-Memory Vector Store filter function. Microsoft fixed both vulnerabilities in version 1.39.4 or higher.
Aug 7, 2026 · 6 sources
Aug 6, 2026 · 4 sources
Aug 10, 2026 · 3 sources
Aug 9, 2026 · 9 sources
Story comments
Loading comments…