CVE-2026-21537Code Injection in Microsoft Defender FOR Endpoint FOR Linux

CWE-94Code Injection8 documents6 sources
Severity
8.8HIGHNVD
EPSS
0.1%
top 74.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 10
Latest updateFeb 13

Description

Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

1
GHSA
GHSA-c8x6-p29h-wm35: Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adja2026-02-10

📋Vendor Advisories

1
Microsoft
Microsoft Defender for Endpoint Linux Extension Remote Code Execution Vulnerability2026-02-10

🕵️Threat Intelligence

5
Sophos
February’s Patch Tuesday assumes battle stations2026-02-13
Qualys
Microsoft and Adobe Patch Tuesday, February 2026 Security Update Review2026-02-10
Bleepingcomputer
Microsoft February 2026 Patch Tuesday fixes 6 zero-days, 58 flaws2026-02-10
Qualys
Microsoft and Adobe Patch Tuesday, February 2026 Security Update Review | Qualys2026-02-10
Sophos
February’s Patch Tuesday assumes battle stations