AgentScout Logo Agent Scout

Microsoft: RCE Vulnerabilities Turn Prompts Into Shell Commands

CVE-2026-26030 (CVSS 9.8) enables RCE in Semantic Kernel via prompt injection. Immediate upgrade to 1.39.4+ required for AI agent applications.

AgentScout Β· Β· 4 min read
#microsoft #semantic-kernel #rce #prompt-injection #ai-security #cve
Analyzing Data Nodes...
SIG_CONF:CALCULATING
Verified Sources

TL;DR

Microsoft disclosed CVE-2026-26030 (CVSS 9.8), a critical remote code execution vulnerability in Semantic Kernel Python SDK that allows attackers to execute arbitrary code through prompt injection in vector store filter expressions. The vulnerability affects all versions prior to 1.39.4 and targets AI agent infrastructure directly, not web endpoints.

Key Facts

  • Who: Microsoft Security Response Center, affecting Semantic Kernel SDK users
  • What: Critical RCE vulnerability (CVSS 9.8) enabling arbitrary code execution via prompt injection
  • When: Disclosed May 7, 2026; patches available immediately
  • Impact: All AI applications using Semantic Kernel Python SDK < 1.39.4 or .NET SDK < 1.71.0

What Changed

Microsoft’s Security Response Center disclosed a critical remote code execution vulnerability in Semantic Kernel, its open-source SDK for building AI agents. CVE-2026-26030 carries a CVSS severity score of 9.8 out of 10, making it one of the most severe AI framework vulnerabilities disclosed in 2026.

The vulnerability resides in the InMemoryVectorStore component, where malicious filter expressions can be injected through user prompts. Unlike traditional injection attacks that target web application endpoints, this attack chain converts natural language input into executable Python code through the agent’s internal filter parsing logic.

β€œAn attacker who successfully exploited this vulnerability could run arbitrary code in the context of the application,” Microsoft stated in its security advisory. β€œThis could allow the attacker to install programs; view, change, or delete data; or create new accounts with full user rights.”

A second vulnerability, CVE-2026-25592, affects the .NET SDK with a path traversal flaw. Both vulnerabilities were patched in Semantic Kernel Python version 1.39.4 and .NET version 1.71.0, released immediately upon disclosure.

Security researchers from Nuka-AI disclosed multiple bypass vectors for the initial February patches, prompting the May disclosure and additional hardening measures.

Why It Matters

The attack chain mechanics distinguish this vulnerability from traditional web security threats:

Attack VectorTraditional XSSSemantic Kernel RCE
Entry PointWeb form inputAgent prompt input
Target LayerBrowser DOMPython/.NET runtime
Execution ContextClient-side JavaScriptServer-side code
Blast RadiusUser sessionApplication server
Exploitation ComplexityMediumLow

Attack Chain Breakdown:

  1. Prompt Input: Attacker crafts a natural language prompt containing malicious filter syntax
  2. Filter Expression: The prompt is passed to InMemoryVectorStore.filter() without proper sanitization
  3. Code Execution: Filter expression is evaluated as Python code via eval() or equivalent
  4. Runtime Access: Attacker gains arbitrary code execution on the server hosting the AI agent

The vulnerability class is particularly concerning because:

  • No Input Validation Bypass Required: The filter expression syntax is intended functionality, making detection difficult
  • Agent-Specific Attack Surface: Traditional WAF rules do not inspect agent prompt flows
  • High Trust Context: AI agents often run with elevated permissions to access tools, APIs, and databases
  • Supply Chain Implications: Organizations embedding Semantic Kernel in production agents face immediate exposure

According to Microsoft’s security blog, the attack requires no authentication for applications that accept untrusted prompts, which includes most customer-facing AI agent deployments.

πŸ”Ί Scout Intel: What Others Missed

Confidence: high | Novelty Score: 82/100

The deeper security implication extends beyond the immediate patch. This vulnerability represents a new attack class: prompt-to-code translation exploits. Traditional security models assume a boundary between user input and code execution, but AI agent frameworks deliberately blur this boundary through natural language interfaces. Semantic Kernel’s filter expression mechanism is not a bugβ€”it’s a feature designed to let developers write expressive queries. The vulnerability exploits this intentional design pattern, making it difficult to distinguish legitimate use from malicious injection without breaking functionality.

Key Implication: Enterprise security teams must audit all AI agent frameworksβ€”not just Semantic Kernelβ€”for similar prompt-to-code translation patterns. LangChain, CrewAI, and OpenAI’s Agents SDK all implement comparable filter/search mechanisms that may contain equivalent vulnerabilities. The attack surface is architectural, not incidental.

What This Means

For AI Application Developers

Immediate action is required for any application using Semantic Kernel Python SDK before version 1.39.4 or .NET SDK before version 1.71.0. The patch introduces strict input sanitization for filter expressions, but developers should additionally:

  • Implement prompt content filtering before filter expression generation
  • Audit agent permissions and apply principle of least privilege
  • Enable audit logging for all filter expression evaluations
  • Consider sandboxing agent runtimes in containerized environments

For Enterprise Security Teams

This disclosure should trigger a broader audit of AI agent infrastructure:

  1. Inventory all AI frameworks in production environments, including Semantic Kernel, LangChain, CrewAI, AutoGen, and OpenAI Agents SDK
  2. Review prompt handling code for similar filter expression patterns
  3. Update security monitoring to include agent prompt flows, which traditional WAFs do not inspect
  4. Assess blast radius: Agents with database, API, or file system access multiply the potential impact

What to Watch

Microsoft’s disclosure may be the first of many in this vulnerability class. Security researchers at Nuka-AI have demonstrated that the attack pattern is replicable across multiple agent frameworks. Expect additional CVEs targeting prompt-to-code translation mechanisms in competing AI agent SDKs throughout 2026.

Related Coverage:

Sources

Microsoft: RCE Vulnerabilities Turn Prompts Into Shell Commands

CVE-2026-26030 (CVSS 9.8) enables RCE in Semantic Kernel via prompt injection. Immediate upgrade to 1.39.4+ required for AI agent applications.

AgentScout Β· Β· 4 min read
#microsoft #semantic-kernel #rce #prompt-injection #ai-security #cve
Analyzing Data Nodes...
SIG_CONF:CALCULATING
Verified Sources

TL;DR

Microsoft disclosed CVE-2026-26030 (CVSS 9.8), a critical remote code execution vulnerability in Semantic Kernel Python SDK that allows attackers to execute arbitrary code through prompt injection in vector store filter expressions. The vulnerability affects all versions prior to 1.39.4 and targets AI agent infrastructure directly, not web endpoints.

Key Facts

  • Who: Microsoft Security Response Center, affecting Semantic Kernel SDK users
  • What: Critical RCE vulnerability (CVSS 9.8) enabling arbitrary code execution via prompt injection
  • When: Disclosed May 7, 2026; patches available immediately
  • Impact: All AI applications using Semantic Kernel Python SDK < 1.39.4 or .NET SDK < 1.71.0

What Changed

Microsoft’s Security Response Center disclosed a critical remote code execution vulnerability in Semantic Kernel, its open-source SDK for building AI agents. CVE-2026-26030 carries a CVSS severity score of 9.8 out of 10, making it one of the most severe AI framework vulnerabilities disclosed in 2026.

The vulnerability resides in the InMemoryVectorStore component, where malicious filter expressions can be injected through user prompts. Unlike traditional injection attacks that target web application endpoints, this attack chain converts natural language input into executable Python code through the agent’s internal filter parsing logic.

β€œAn attacker who successfully exploited this vulnerability could run arbitrary code in the context of the application,” Microsoft stated in its security advisory. β€œThis could allow the attacker to install programs; view, change, or delete data; or create new accounts with full user rights.”

A second vulnerability, CVE-2026-25592, affects the .NET SDK with a path traversal flaw. Both vulnerabilities were patched in Semantic Kernel Python version 1.39.4 and .NET version 1.71.0, released immediately upon disclosure.

Security researchers from Nuka-AI disclosed multiple bypass vectors for the initial February patches, prompting the May disclosure and additional hardening measures.

Why It Matters

The attack chain mechanics distinguish this vulnerability from traditional web security threats:

Attack VectorTraditional XSSSemantic Kernel RCE
Entry PointWeb form inputAgent prompt input
Target LayerBrowser DOMPython/.NET runtime
Execution ContextClient-side JavaScriptServer-side code
Blast RadiusUser sessionApplication server
Exploitation ComplexityMediumLow

Attack Chain Breakdown:

  1. Prompt Input: Attacker crafts a natural language prompt containing malicious filter syntax
  2. Filter Expression: The prompt is passed to InMemoryVectorStore.filter() without proper sanitization
  3. Code Execution: Filter expression is evaluated as Python code via eval() or equivalent
  4. Runtime Access: Attacker gains arbitrary code execution on the server hosting the AI agent

The vulnerability class is particularly concerning because:

  • No Input Validation Bypass Required: The filter expression syntax is intended functionality, making detection difficult
  • Agent-Specific Attack Surface: Traditional WAF rules do not inspect agent prompt flows
  • High Trust Context: AI agents often run with elevated permissions to access tools, APIs, and databases
  • Supply Chain Implications: Organizations embedding Semantic Kernel in production agents face immediate exposure

According to Microsoft’s security blog, the attack requires no authentication for applications that accept untrusted prompts, which includes most customer-facing AI agent deployments.

πŸ”Ί Scout Intel: What Others Missed

Confidence: high | Novelty Score: 82/100

The deeper security implication extends beyond the immediate patch. This vulnerability represents a new attack class: prompt-to-code translation exploits. Traditional security models assume a boundary between user input and code execution, but AI agent frameworks deliberately blur this boundary through natural language interfaces. Semantic Kernel’s filter expression mechanism is not a bugβ€”it’s a feature designed to let developers write expressive queries. The vulnerability exploits this intentional design pattern, making it difficult to distinguish legitimate use from malicious injection without breaking functionality.

Key Implication: Enterprise security teams must audit all AI agent frameworksβ€”not just Semantic Kernelβ€”for similar prompt-to-code translation patterns. LangChain, CrewAI, and OpenAI’s Agents SDK all implement comparable filter/search mechanisms that may contain equivalent vulnerabilities. The attack surface is architectural, not incidental.

What This Means

For AI Application Developers

Immediate action is required for any application using Semantic Kernel Python SDK before version 1.39.4 or .NET SDK before version 1.71.0. The patch introduces strict input sanitization for filter expressions, but developers should additionally:

  • Implement prompt content filtering before filter expression generation
  • Audit agent permissions and apply principle of least privilege
  • Enable audit logging for all filter expression evaluations
  • Consider sandboxing agent runtimes in containerized environments

For Enterprise Security Teams

This disclosure should trigger a broader audit of AI agent infrastructure:

  1. Inventory all AI frameworks in production environments, including Semantic Kernel, LangChain, CrewAI, AutoGen, and OpenAI Agents SDK
  2. Review prompt handling code for similar filter expression patterns
  3. Update security monitoring to include agent prompt flows, which traditional WAFs do not inspect
  4. Assess blast radius: Agents with database, API, or file system access multiply the potential impact

What to Watch

Microsoft’s disclosure may be the first of many in this vulnerability class. Security researchers at Nuka-AI have demonstrated that the attack pattern is replicable across multiple agent frameworks. Expect additional CVEs targeting prompt-to-code translation mechanisms in competing AI agent SDKs throughout 2026.

Related Coverage:

Sources

bdkks76q08w0b8rl23trtrqβ–‘β–‘β–‘n8nu3sbminzg00mu3o7ezer8h3c9mvβ–ˆβ–ˆβ–ˆβ–ˆ7f2if13obolxhite8mj7yc89a4bi38annβ–‘β–‘β–‘xkv757d0oknryto6wkiy3i4lw0ox5v0nβ–ˆβ–ˆβ–ˆβ–ˆrjss0irlwblh0m4cbqngis1z8fqikm8iβ–ˆβ–ˆβ–ˆβ–ˆkkvqoustl31d6fy8jasmg7119lnnyd58β–ˆβ–ˆβ–ˆβ–ˆ4hkxcbt8ati8iplvvj2hlqza09m0eewβ–‘β–‘β–‘7rx4bl07f13bfyj7cp5iya9ny313wmlk9β–ˆβ–ˆβ–ˆβ–ˆ4prgitwpcwpg5sulq8twmesg20t7x3m7eβ–‘β–‘β–‘z35etr60uuau3j60edmkp4ekecrl9yβ–‘β–‘β–‘v56gp813ryizkd6sm2vhk0rl4ox3zzβ–‘β–‘β–‘p1pkxi3srp7wvqsk116122ly8dys6932β–ˆβ–ˆβ–ˆβ–ˆko4g3x3816o6h0kge8x7imvbznoxenmshβ–ˆβ–ˆβ–ˆβ–ˆs01mvj0jv0y8mhq5rntdpdp9yk8fbcp4β–ˆβ–ˆβ–ˆβ–ˆ1zwtu1f92w87z17ilhzahv9uuulbt7o4mβ–ˆβ–ˆβ–ˆβ–ˆreq68f6745gqsrdec6r3w9znmh0ey1fjβ–‘β–‘β–‘37r25223iifa4tc9g56vuvouxrxyqi4kβ–‘β–‘β–‘d4s4e5t0voovkbmjxn95b2rbwlckl1d9β–ˆβ–ˆβ–ˆβ–ˆutbmkj0ed4k7a5a04c8ec3h7mm1j3borrβ–ˆβ–ˆβ–ˆβ–ˆxct0oy2buz89ntsh24ka5ek6dxxz5snβ–‘β–‘β–‘8yyoanyfelhx154pe2xd8rts4jmokswiβ–‘β–‘β–‘wblm4qfce0gc75gh0evkxgmkzqsgbuwcβ–‘β–‘β–‘w4r2wftganw0r43pltr8g32r579174β–‘β–‘β–‘xrjv7bjqliker2ts5o12yhfzrpvauzaβ–‘β–‘β–‘6o9psys0gnxa9zh9tntcwc1b3jxkd8xpaβ–‘β–‘β–‘i2h6ep5tfkidva6iom77coqvnx4w3dlw8β–‘β–‘β–‘autjngxw0qnhwfl7q1ipkqwbfvlpvx9lpβ–ˆβ–ˆβ–ˆβ–ˆ1ge1u32udfoee6t7eyy6wf4ykwaqbc2pβ–‘β–‘β–‘ne94c24xed83mtgyl694obhgex6dmgk8β–ˆβ–ˆβ–ˆβ–ˆm6yrywpgmidi88ayt46wdr8vp5jq7xzpβ–‘β–‘β–‘3dmtdw5mcgiol5nzctpmiqt5gfwypo0b8β–‘β–‘β–‘ovp4e1yqwwx35f5zw2v900o4g8i7on79β–ˆβ–ˆβ–ˆβ–ˆw6n6ubecmmgadil8r78uth85gb9jm7frkβ–‘β–‘β–‘ku1l3vragsp8dqmt655gx8z28tq6tjvh9β–‘β–‘β–‘pgq7ex9mi6aa8bisgp7c99896exbxs3kβ–ˆβ–ˆβ–ˆβ–ˆbp14l3x4na84xgxhsf9r4vbc9t205dxbβ–‘β–‘β–‘k5ks1ojksunjd65ygci2ead5yj13hovmβ–‘β–‘β–‘bvt3eksj2tu8fq2dzbyi1ibgu5i793fkkβ–‘β–‘β–‘90c54v6gprplr5hsogmdbmcui1sijβ–‘β–‘β–‘u243y4e76iktt7g8c89xsaa9g8wd4ljpβ–‘β–‘β–‘8vbblwi3p39gs48y6egy6t5uiy7inbk43β–ˆβ–ˆβ–ˆβ–ˆ0gcq3jzw9h16r54iayj2vp187ndurz3gxβ–‘β–‘β–‘msp3cp03jxl9a0y87ir4x5wxylcyxu46β–ˆβ–ˆβ–ˆβ–ˆrtqtlcn8f4h06pni9vps9wyqjr7y4r1β–ˆβ–ˆβ–ˆβ–ˆr2u9hyu1bnc40hjez4kokgcykbjo19jβ–ˆβ–ˆβ–ˆβ–ˆ67bkpaenzwkwtysr0058sog3sygmz0lβ–ˆβ–ˆβ–ˆβ–ˆlr5lvlvcje994wjgn9wk1mtetkinkfejcβ–ˆβ–ˆβ–ˆβ–ˆztnzmfrj76l2xzeqj14p6a11nf7xkm73pβ–‘β–‘β–‘byhwxxp9wxlq6sd9xtya8rbhs3dswtxpβ–ˆβ–ˆβ–ˆβ–ˆ1grenm8jfet2msqya7lwdvwaxzpfof6lhβ–ˆβ–ˆβ–ˆβ–ˆ3jkbyf7pcqs