Aug 17, 2026 · Subject: HPC Pack RCE (9.8), KVM guest escape, 3 more
HPC Pack 9.8 deserialization RCE, KVM guest-to-host escape, and Teams XSS
Monday starts with a 9.8 you might not have on your radar. CVE-2026-59124 is an unauthenticated deserialization RCE in Microsoft HPC Pack 2019: no login, no user interaction, trivial attack surface. Nobody's exploiting it yet, but that won't last long if your HPC nodes are internet-reachable. Four more behind it, including a KVM nested-virt bug that lets a guest VM mess with host interrupts and two XSS issues in Teams for Android and Azure Storage Explorer.
One item / urgency verdict
CVE-2026-59124
An attacker can send malicious serialized data to Microsoft HPC Pack 2019 over the network and get code execution, no authentication required.
Apply the latest Microsoft security update for HPC Pack 2019 and verify your HPC head nodes are not exposed to the internet.