Microsoft PowerShell Patches Two RCE Flaws
Microsoft patched two vulnerabilities in PowerShell and Malware Protection Engine allowing remote code execution and privilege escalation.
CERT-FR issued an advisory covering two vulnerabilities affecting Microsoft's Malware Protection Engine and PowerShell (versions 7.4 prior to 7.4.19.0, 7.5 prior to 7.5.10.0, and 7.6 prior to 7.6.5). The flaws, tracked as CVE-2026-50523 and CVE-2026-69414, could allow an attacker to achieve remote code execution and privilege escalation on affected systems.
No indication of active exploitation is provided in the advisory. Microsoft has released security bulletins detailing patches; affected organizations should update PowerShell to the fixed versions and apply the corresponding Malware Protection Engine updates per Microsoft's guidance.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1035
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free