CVE-2026-50523
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to
CVSS
7.8
Alto
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 14 ago 2026 · Última mod.: 14 ago 2026 · CWE-77
Sin historial EPSS suficiente todavía.
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-197717.2 ALT85.2%
——26A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manipulation of the argument MaxHops/Timeout/Size leads to os command injection. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.1dCVE-2026-197479.8 CRÍ82.3%
——25A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is possible to be carried out remotely.1dCVE-2026-73250—2.9%
——1Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the Notepad++ Windows 11 x64 and ARM64 installer passes the attacker-influenced installation directory `$INSTDIR` from PowerEditor/installer/nppSetup.nsi into a PowerShell `-Command` string used by RegisterMSIX to invoke Add-AppxPackage, allowing PowerShell subexpression syntax such as `$()` in the installation path to execute commands in the installer's security context when the context menu component is selected. This issue is fixed in version 8.9.7.2dCVE-2026-687927.8 ALT46.5%
——14Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally.1dCVE-2026-656567.8 ALT29.4%
——9Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally.1dCVE-2026-491798.8 ALT53.9%
——16Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.2d