CyberICT

CVE-2026-41094

Microsoft · Published May 12, 2026

CVSS v3.1

HIGH
Patch availableGet patch

Description

Microsoft Data Formulator Remote Code Execution Vulnerability. Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network.

Affected Products

  • Microsoft Data Formulator

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C