CVE-2026-70338HighCVSS 7.8

Microsoft PowerShell Security Feature Bypass Vulnerability

Published
August 14, 2026
Last Modified

🔗 CVE IDs covered (1)

📋 Description

Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

🎯 Affected products3

  • PowerShell 7.4
  • PowerShell 7.5
  • PowerShell 7.6

✅ Remediation

Security Update — fixed build 7.4.19.0 Security Update — fixed build 7.5.10.0 Security Update — fixed build 7.6.5

🔗 References (1)