PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-58612 Microsoft CVE debrief

A server-side request forgery (SSRF) vulnerability exists in Microsoft PowerShell Core, which could allow an unauthorized attacker to disclose information over a network. The vulnerability affects various versions of PowerShell, including 7.4, 7.5, and 7.6. Microsoft has released an advisory and patch for this vulnerability. Defenders should assess exposure and prioritize patching for affected PowerShell deployments. The vulnerability requires verification and patching to prevent potential exploitation. Affected versions have been identified, and an advisory is available for review. The CVE record and source item provide details on the vulnerability and references to vendor adviso

Vendor
Microsoft
Product
PowerShell 7.4
CVSS
HIGH 7.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-10-08
Advisory published
2026-08-11
Advisory updated
2026-10-08

Who should care

Defenders responsible for PowerShell deployments, particularly those using affected versions (7.4, 7.5, 7.6), should assess exposure and prioritize patching.

Why it matters

Defenders should care about this vulnerability as it could lead to information disclosure in PowerShell deployments, particularly in versions 7.4, 7.5, and 7.6. The vulnerability requires verification and patching to prevent potential exploitation.

  • Potential information disclosure over the network
  • Need to verify and patch affected PowerShell versions
  • Possible impact on systems using PowerShell for automation or scripting

Technical summary

The vulnerability exists in Microsoft PowerShell Core due to a server-side request forgery (SSRF) weakness, allowing an unauthorized attacker to disclose information over a network. Affected versions include PowerShell 7.4, 7.5, and 7.6. Microsoft has released an advisory and patch for this vulnerability.

Defensive priority

Defenders should prioritize patching affected PowerShell versions and monitoring for potential information disclosure attempts.

Recommended defensive actions

  • Patch affected PowerShell versions (7.4, 7.5, 7.6) with the latest updates
  • Monitor for potential information disclosure attempts
  • Review and update affected systems' configurations

Evidence notes

The CVE record and source item provide details on the vulnerability, affected versions, and references to vendor advisories. The vulnerability exists in Microsoft PowerShell Core due to a server-side request forgery (SSRF) weakness. Defenders should verify affected PowerShell versions and review vendor guidance for patching. Evidence limits are based on available source information, and further verification is recommended. The source item and CVE record are official sources for this

Sources and references

Verified primary and authoritative sources

  • CVE-2026-58612 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-58612

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-58612 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58612

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • PowerShell Information Disclosure Vulnerability

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/58xxx/CVE-2026-58612.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58612

    Supplemental source - vendor-advisory, patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.