Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-59124: Microsoft HPC Pack Remote Code Execution Risk
CVE-2026-59124 · published 23 days ago
Summary
Microsoft HPC Pack's ability to execute code can be exploited by unauthorized users over a network, potentially allowing them to access or modify sensitive data. This is a serious risk because it could lead to data theft or system compromise. To mitigate this risk, ensure that Microsoft HPC Pack is properly configured and only accessible to trusted users.
What to do
- Update microsoft windows_app to version 2.0.1314.0 or later.
- Update microsoft microsoft hpc pack 2019 to version 6.3.8359 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| microsoft | windows app client for windows desktop |
< 2.0.1309.0 < 2.0.1314.0 |
| microsoft | windows_app |
< 2.0.1314.0 cpe:2.3:a:microsoft:windows_app:*:*:*:*:*:windows:*:* |
| microsoft | microsoft hpc pack 2019 | < 6.3.8359 |
Original advisory text
Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-59124 vendor-advisory patch
Severity
9.8
Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS 2%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published11 Aug 2026
Updated30 Aug 2026
First seen11 Aug 2026
Monitor software like this
Free during beta