CVE-2026-21537
Microsoft · Published February 10, 2026
8.8
CVSS v3.1
HIGHPatch availableGet patch
Description
Microsoft Defender for Endpoint Linux Extension Remote Code Execution Vulnerability. Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network.
Affected Products
- Microsoft Defender for Endpoint for Linux
CVSS Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C