PatchSiren cyber security CVE debrief
CVE-2026-58612 Microsoft CVE debrief
A server-side request forgery (SSRF) vulnerability exists in Microsoft PowerShell Core, which could allow an unauthorized attacker to disclose information over a network. The vulnerability affects various versions of PowerShell, including 7.4, 7.5, and 7.6. Microsoft has released an advisory and patch for this vulnerability. Defenders should assess exposure and prioritize patching for affected PowerShell deployments. The vulnerability requires verification and patching to prevent potential exploitation. Affected versions have been identified, and an advisory is available for review. The CVE record and source item provide details on the vulnerability and references to vendor adviso
- Vendor
- Microsoft
- Product
- PowerShell 7.4
- CVSS
- HIGH 7.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for PowerShell deployments, particularly those using affected versions (7.4, 7.5, 7.6), should assess exposure and prioritize patching.
Why it matters
Defenders should care about this vulnerability as it could lead to information disclosure in PowerShell deployments, particularly in versions 7.4, 7.5, and 7.6. The vulnerability requires verification and patching to prevent potential exploitation.
- Potential information disclosure over the network
- Need to verify and patch affected PowerShell versions
- Possible impact on systems using PowerShell for automation or scripting
Technical summary
The vulnerability exists in Microsoft PowerShell Core due to a server-side request forgery (SSRF) weakness, allowing an unauthorized attacker to disclose information over a network. Affected versions include PowerShell 7.4, 7.5, and 7.6. Microsoft has released an advisory and patch for this vulnerability.
Defensive priority
Defenders should prioritize patching affected PowerShell versions and monitoring for potential information disclosure attempts.
Recommended defensive actions
- Patch affected PowerShell versions (7.4, 7.5, 7.6) with the latest updates
- Monitor for potential information disclosure attempts
- Review and update affected systems' configurations
Evidence notes
The CVE record and source item provide details on the vulnerability, affected versions, and references to vendor advisories. The vulnerability exists in Microsoft PowerShell Core due to a server-side request forgery (SSRF) weakness. Defenders should verify affected PowerShell versions and review vendor guidance for patching. Evidence limits are based on available source information, and further verification is recommended. The source item and CVE record are official sources for this
Sources and references
Verified primary and authoritative sources
-
CVE-2026-58612 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-58612
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-58612 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-58612
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
PowerShell Information Disclosure Vulnerability
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/58xxx/CVE-2026-58612.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58612
Supplemental source - vendor-advisory, patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.