CVE-2026-21537

HIGH

Microsoft Defender for Endpoint for Linux 101.0.0-1.0.8.9 - Unauthenticated Remote Code Execution

Title source: llm
STIX 2.1

Description

Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network.

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0009
EPSS Percentile 25.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
microsoft/defender_for_endpoint
Microsoft/Microsoft Defender for Endpoint for Linux 101.0.0 - 1.0.9.0
Published Feb 10, 2026
Tracked Since Feb 18, 2026