CyberICT

CVE-2026-21537

Microsoft · Published February 10, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Microsoft Defender for Endpoint Linux Extension Remote Code Execution Vulnerability. Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network.

Affected Products

  • Microsoft Defender for Endpoint for Linux

CVSS Vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C