CVE
CVE-2026-50523
0field notes · 2digests CVSS 7.8
The verdict
A command injection bug in Microsoft PowerShell lets an authorized local attacker execute arbitrary code. The attacker needs local access and some level of authorization first, so this isn't a remote drive-by. But if someone already has a foothold on a box, they can use this to escalate or pivot through crafted PowerShell input.
Patch urgency · Patch this week
Daily digests