Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-59124: Microsoft HPC Pack Remote Code Execution Risk

CVE-2026-59124 · published 23 days ago
Summary

Microsoft HPC Pack's ability to execute code can be exploited by unauthorized users over a network, potentially allowing them to access or modify sensitive data. This is a serious risk because it could lead to data theft or system compromise. To mitigate this risk, ensure that Microsoft HPC Pack is properly configured and only accessible to trusted users.

What to do
  • Update microsoft windows_app to version 2.0.1314.0 or later.
  • Update microsoft microsoft hpc pack 2019 to version 6.3.8359 or later.
Affected software
VendorProductAffected versions
microsoft windows app client for windows desktop < 2.0.1309.0
< 2.0.1314.0
microsoft windows_app < 2.0.1314.0
cpe:2.3:a:microsoft:windows_app:*:*:*:*:*:windows:*:*
microsoft microsoft hpc pack 2019 < 6.3.8359
Original advisory text
Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
Severity
9.8 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS 2%
Type
CWE-502Deserialization of Untrusted Data
Timeline
Published11 Aug 2026
Updated30 Aug 2026
First seen11 Aug 2026
Sources
CVE-2026-59124 · MITRE
Monitor software like this
Free during beta