Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 26 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Feb 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:microsoft:defender_for_endpoint:-:*:*:*:*:linux:*:* |
Tue, 10 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network. | |
| Title | Microsoft Defender for Endpoint Linux Extension Remote Code Execution Vulnerability | |
| First Time appeared |
Microsoft
Microsoft defender For Endpoint |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:microsoft:defender_for_endpoint:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft defender For Endpoint |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-05-11T21:25:33.944Z
Reserved: 2025-12-30T18:10:54.848Z
Link: CVE-2026-21537
Updated: 2026-02-25T15:43:10.379Z
Status : Analyzed
Published: 2026-02-10T18:16:35.970
Modified: 2026-02-11T21:50:25.840
Link: CVE-2026-21537
No data.
OpenCVE Enrichment
Updated: 2026-04-15T17:45:10Z