CVE-2026-23654 is a high-severity vulnerability affecting Microsoft's zero_shot_scfoundation, stemming from a dependency on a vulnerable third-party component within its GitHub repository. This flaw allows an unauthorized attacker to achieve remote code execution over a network, carrying a CVSS score of 8.8 HIGH. Exploitation requires user interaction but has low attack complexity and no privileges, potentially leading to high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation or public exploit code, though it has been discussed in March 2026 Patch Tuesday reviews.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.1.1CPE matchmatch criteria | cpe:2.3:a:microsoft:zero-shot-scfoundation:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.