CVE-2026-41094
Microsoft · Published May 12, 2026
8.8
CVSS v3.1
HIGHPatch availableGet patch
Description
Microsoft Data Formulator Remote Code Execution Vulnerability. Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network.
Affected Products
- Microsoft Data Formulator
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C