Remote Code Execution Vulnerability in Microsoft's Python SDK for Semantic Kernel
CVE-2026-26030

10CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
19 February 2026

What is CVE-2026-26030?

The Semantic Kernel Python SDK from Microsoft contains a flaw within the InMemoryVectorStore filter functionality that may allow an attacker to execute arbitrary code remotely. This vulnerability impacts versions of the SDK released prior to 1.39.4. Users are strongly advised to upgrade to version 1.39.4 or later to mitigate this risk. As an alternative measure, it is recommended to avoid utilizing the InMemoryVectorStore in production environments until the upgrade is applied. For more detailed information, please refer to the relevant security advisories and release notes.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

semantic-kernel < 1.39.4

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.