CVE-2026-54120
Microsoft · Published July 23, 2026
9.9
CVSS v3.1
CRITICALPatch availableGet patch
Description
Microsoft Surface Remote Code Execution Vulnerability. Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.
Affected Products
- Surface Management Services
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C