CyberICT

CVE-2026-54120

Microsoft · Published July 23, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

Microsoft Surface Remote Code Execution Vulnerability. Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

Affected Products

  • Surface Management Services

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C