CVE-2026-26030: Microsoft Semantic Kernel Additional Command Injection Vulnerability
Another command injection vulnerability in Microsoft Semantic Kernel related to insecure shell command handling.
Another command injection vulnerability in Microsoft Semantic Kernel related to insecure shell command handling.
A vulnerability in Microsoft's Semantic Kernel agent framework where model output reaching a shell can lead to command injection. Patched by Microsoft.
A GitHub Actions workflow injection vulnerability allowed crafted issues to execute commands in a CI/CD pipeline. The flaw was fixed by using…
Cybersecurity researchers at Novee Security have identified a critical exploitable pattern in CI/CD workflows, codenamed Cordyceps, that allows unauthenticated attackers to hijack…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding active exploitation of a critical vulnerability in Lantronix EDS5000…