PatchDayAlert

CVE

CVE-2026-59124

0field notes · 1digest CVSS 9.8

The verdict

An attacker can send malicious serialized data to Microsoft HPC Pack 2019 over the network and get code execution, no authentication required. CVSS 9.8 and no user interaction needed, so anything internet-reachable is a sitting duck. Not yet exploited in the wild, but the attack surface is trivial enough that you shouldn't wait.

Patch urgency · Patch immediately


Daily digests