CVE-2026-26030
Semantic Kernel, Microsoft's semantic kernel Python SDK, has a remote code execution vulnerability in versions prior to 1.39.4, specifically within the `InMemoryVectorStore` filter functionality. The problem has been fixed in version `python-1.39.4`. Users should upgrade this version or higher. As a workaround, avoid using `InMemoryVectorStore` for production scenarios.
- Affected products
- Inmemoryvectorstore, Semantic-Kernel
- Microsoft Semantic Kernel
- < 1.39.4
- Fix
- Available
- CVSS 3.1
- 9.9 CRITICAL
- EPSS
- 3.7% (89th percentile)
- Weakness
- CWE-94
- NVD status
- Analyzed
- Published
- 2026-02-19
CVE-2026-26030 at NVD
2 known exploits for CVE-2026-26030
Proof-of-concept code and exploit modules indexed by Sploitus