PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23652 Microsoft CVE debrief

A critical command injection vulnerability in Microsoft Power Pages enables unauthenticated remote code execution over the network. The vulnerability, published 2026-05-22 and last modified 2026-05-26, carries a CVSS 3.1 score of 10.0 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Microsoft has assigned CWE-77 (Improper Neutralization of Special Elements used in a Command). The NVD entry remains 'Undergoing Analysis' as of the last source modification. No KEV listing or known ransomware campaign use has been identified. Organizations using Microsoft Power Pages should monitor Microsoft's Security Response Center for patch availability and apply updates per vendor guidance.

Vendor
Microsoft
Product
Microsoft Power Pages
CVSS
CRITICAL 10
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-22
Original CVE updated
2026-05-27
Advisory published
2026-05-22
Advisory updated
2026-05-27

Who should care

Organizations operating Microsoft Power Pages environments, security teams managing low-code/no-code platforms, and incident response teams preparing for potential unauthenticated RCE scenarios.

Technical summary

Microsoft Power Pages contains a command injection vulnerability (CWE-77) allowing unauthenticated attackers to execute arbitrary code remotely. The CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H indicates network exploitable, low complexity, no privileges required, no user interaction, scope change, and complete confidentiality/integrity/availability impact. The vulnerability is rated CRITICAL with maximum CVSS score 10.0.

Defensive priority

critical

Recommended defensive actions

  • Monitor Microsoft Security Response Center for security update release and apply patches immediately upon availability
  • Review Power Pages deployments for unauthorized configuration changes or anomalous administrative activity
  • Implement network segmentation to limit exposure of Power Pages instances to untrusted networks
  • Enable comprehensive logging and monitoring for Power Pages environments to detect potential exploitation attempts
  • Prepare incident response procedures for potential compromise given critical severity and unauthenticated exploitation vector

Evidence notes

CVE description confirms command injection in Microsoft Power Pages with network-based attack vector. CVSS 3.1 vector indicates unauthenticated exploitation (PR:N), low attack complexity (AC:L), and scope change (S:C) suggesting impact beyond vulnerable component. Microsoft MSRC reference provided as primary source. NVD status 'Undergoing Analysis' indicates ongoing assessment.

Official resources

2026-05-22