CVE-2026-59124: Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability
Overview
- Severity
- Critical (CVSS 9.8)
- CVSS Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Remote Code Execution
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- More Likely
- Patch Tuesday
- 2026-Aug
- Released
- 2026-08-11
- Last Updated
- 2026-08-16
- EPSS Score
- 1.53% (percentile: 73.7%)
Description
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
FAQ
How could an attacker exploit this vulnerability?
An attacker could exploit this vulnerability by submitting a specially crafted payload to an affected service that deserializes untrusted data. Successful exploitation could allow the attacker to execute code on the target system.
Affected Products (1)
Azure
Security Updates (1)
Acknowledgments
P1hcn
Revision History
- 2026-08-11: Information published.
- 2026-08-16: Corrected the listed software in the Security Updates table. Microsoft recommends installing the security update as soon as possible.