14:36
2026-09-17
dev.to
ai-agents
A Prompt Injection Turned Into a Shell: Inside Semantic Kernel's Two RCE CVEs
Microsoft disclosed two remote code execution vulnerabilities in its open-source Semantic Kernel agent framework, CVE-2026-26030 and CVE-2026-25592, both stemming from model-controlled input reaching …