← Back to browse · API

CVE-2026-26030

Severity
CRITICAL
CVSS
10.0
EPSS
0.03712
Risk score
41.3
CISA KEV
No
PoC
No
Published
2026-02-19
Modified
2026-02-26
First seen
2026-08-06
Aliases
CNVD-2026-12909, EUVD-2026-8014, GHSA-XJW9-4GW8-4RQX, PYSEC-2026-163
Products
Microsoft Semantic Kernel <1.39.4, Microsoft:semantic-kernel < 1.39.4
Sources
cnvd CNVD-2026-12909
euvd EUVD-2026-8014

Description

Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The problem has been fixed in version `python-1.39.4`. Users should upgrade this version or higher. As a workaround, avoid using `InMemoryVectorStore` for production scenarios.

References