Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Microsoft Discloses Remote Code Execution Vulnerabilities in AI Agent Frameworks
00

Microsoft Discloses Remote Code Execution Vulnerabilities in AI Agent Frameworks

May 8, 2026

Microsoft Security disclosed on May 8, 2026 two critical remote code execution vulnerabilities in Microsoft Semantic Kernel, an open-source AI agent framework with over 27,000 GitHub stars. CVE-2026-25592 and CVE-2026-26030 allowed attackers to achieve unauthorized code execution through prompt injection attacks exploiting the framework's In-Memory Vector Store filter function. Microsoft fixed both vulnerabilities in version 1.39.4 or higher.

AI agent security risks

  • ▪If an attacker can control the parameters passed into AI agent plugins via prompt injection, the agent may be driven to perform actions beyond its intended use

Semantic Kernel vulnerabilities

  • ▪The article about Microsoft Semantic Kernel vulnerabilities was published on May 8, 2026
  • ▪CVE-2026-25592 and CVE-2026-26030 could allow an attacker to achieve unauthorized code execution by leveraging injection attacks specifically targeted at agents built within Microsoft Semantic Kernel
  • ▪CVE-2026-25592 and CVE-2026-26030 in Microsoft Semantic Kernel have been fixed
  • ▪Microsoft Semantic Kernel is an open-source framework for building AI agents and integrating AI models into applications with over 27,000 stars on GitHub
  • ▪Two critical vulnerabilities identified in Microsoft Semantic Kernel are CVE-2026-25592 and CVE-2026-26030

CVE-2026-26030 exploitation mechanics

  • ▪The default filter function in Microsoft Semantic Kernel's In-Memory Vector Store is implemented as a Python lambda expression executed using eval()
  • ▪CVE-2026-25592 allows an attacker to bypass a cloud-hosted sandbox, write a malicious payload directly to the host device's Windows Startup folder, and achieve full remote code execution with a single prompt
  • ▪CVE-2026-26030 enables an attacker to achieve remote code execution from a prompt when both required conditions are met
  • ▪CVE-2026-26030 exploitation requires the attacker to have a prompt injection vector allowing influence over the agent's inputs
  • ▪CVE-2026-26030 exploitation requires the targeted agent to have the Search Plugin backed by In-Memory Vector Store functionality using the default configuration
  • ▪The vulnerability in Microsoft Semantic Kernel's default filter function is that kwargs[param.name] is AI model-controlled and not sanitized

Blocklist bypass technique

  • ▪The Microsoft Semantic Kernel validator scans every element in the code for dangerous identifiers and attributes including eval, exec, open, and __import__
  • ▪The exploit payload bypassed the Microsoft Semantic Kernel blocklist because it used attributes not in the blocklist including __name__, load_module, system, and BuiltinImporter
  • ▪The Microsoft Semantic Kernel validator only allows lambda expressions and rejects full code blocks such as import statements or class definitions
  • ▪Microsoft Semantic Kernel implemented a validator that parses the filter string into an Abstract Syntax Tree before execution to prevent remote code execution risk

Patching guidance

  • ▪Upgrading the Python semantic-kernel dependency to version 1.39.4 or higher mitigates the CVE-2026-26030 risk
  • ▪The vulnerable window for CVE-2026-26030 is from the moment a vulnerable Semantic Kernel Python version was deployed until the moment version 1.39.4 or later was installed
  • ▪An agent is vulnerable to CVE-2026-26030 if it uses the Python package semantic-kernel and is running a framework version prior to 1.39.4
  • ▪The Microsoft Semantic Kernel team implemented a fix for CVE-2026-26030 using four layers of protection including AST node-type allowlist, function call allowlist, dangerous attributes blocklist, and name node restriction

1 source

Microsoft
When prompts become shells: RCE vulnerabilities in AI agent frameworks | Microsoft Security Blog
View source article

Featured stories

View more in AI agents

Nvidia releases Open Agent Safety Platform to contain AI agents after security incidents

Sep 28, 2026 · 8 sources

OpenAI and Anthropic investigate tens of thousands of rogue AI agent incidents

Sep 26, 2026 · 2 sources

OpenAI agents exposed 53 ChatGPT user images in research incident

Sep 25, 2026 · 4 sources

OpenAI pauses most capable models after agents exploit loopholes and leak data

Sep 25, 2026 · 2 sources

Story comments

Loading comments…

Topics

AI agentsAI for developersAI securityAI safety & social impactMicrosoft

Featured stories

View more in AI agents

Nvidia releases Open Agent Safety Platform to contain AI agents after security incidents

Sep 28, 2026 · 8 sources

OpenAI and Anthropic investigate tens of thousands of rogue AI agent incidents

Sep 26, 2026 · 2 sources

OpenAI agents exposed 53 ChatGPT user images in research incident

Sep 25, 2026 · 4 sources

OpenAI pauses most capable models after agents exploit loopholes and leak data

Sep 25, 2026 · 2 sources