Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-26030

41
FAUCET Score

CVE-2026-26030 is a critical remote code execution (RCE) vulnerability affecting Microsoft's Semantic Kernel Python SDK versions prior to 1.39.4, specifically within the InMemoryVectorStore filter functionality. With a CVSS score of 9.9, this vulnerability allows an authenticated attacker to execute arbitrary code remotely with low attack complexity, leading to high impacts on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion, indicating high awareness. Users are strongly advised to upgrade to version 1.39.4 or higher, or as a workaround, avoid using InMemoryVectorStore in production environments.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.39.4CPE matchmatch criteria
cpe:2.3:a:microsoft:semantic_kernel:*:*:*:*:*:python:*:*

CVSS Data

CVSS version used by this source: 3.1

9.9CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.1
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.71%
Probability of exploitation in next 30 days
EPSS Percentile
88.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0371 is in the 90th percentile among its peer group of 1,124 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: Microsoft Semantic Kernel Python SDKFixed in: 1.39.4
View patch
pippatch availablevia ghsa
Product: semantic-kernelFixed in: 1.39.4

Vendor Advisories (2)

microsoft2026-Mar/CVE-2026-26030Important

GitHub: CVE-2026-26030 Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable

Mar 10, 2026
pipGHSA-xjw9-4gw8-4rqxcritical

Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution

Feb 19, 2026

References

github.com / microsoft/semantic-kernel/pull/13505
Issue TrackingPatch
github.com / microsoft/semantic-kernel/releases/tag/python-1.39.4
Release Notes
github.com / microsoft/semantic-kernel/security/advisories/GHSA-xjw9-4gw8-4rqx
PatchVendor Advisory