CVE-2026-23652: Microsoft Power Pages Remote Code Execution Vulnerability
Published May 21, 2026
·Updated
Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.
Other sources
Microsoft Power Pages Remote Code Execution Vulnerability
— Microsoft
Affected Software
2 affected components
Microsoft Power Pages
Microsoft Power Pages
Event History
May 21, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
May 22, 2026
CVE Published
via MITRE·10:03 PM
Data Sourced
via MITRE·10:03 PM
DescriptionSeverity
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-23652?
CVE-2026-23652 has a critical severity rating of 10.
2
How do I fix CVE-2026-23652?
To fix CVE-2026-23652, update Microsoft Power Pages to the latest security patch provided by Microsoft.
3
What type of vulnerability is CVE-2026-23652?
CVE-2026-23652 is classified as a Command Injection vulnerability.
4
What are the potential impacts of CVE-2026-23652?
CVE-2026-23652 can allow an unauthorized attacker to execute arbitrary code over a network.
5
In which software is CVE-2026-23652 found?
CVE-2026-23652 is found in Microsoft Power Pages.