CVE-2026-59124
Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability
Description
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
In plain language
AI Act nowCVE-2026-59124 is a remote “run arbitrary code” flaw in Microsoft HPC Pack 2019 that can let an attacker take over your system over the network; if you use HPC Pack 2019, you should act immediately and install the fixed update.
CVE-2026-59124 is a remote code execution vulnerability in Microsoft HPC Pack 2019 (CWE-502 deserialization of untrusted data), where an attacker can send crafted network data to trigger code execution without needing user interaction.
What to do now
- Check whether your organization is running Microsoft HPC Pack 2019, and note the installed version.
- Check whether you also have the related “windows app” component installed and note its version.
- If Microsoft HPC Pack 2019 is installed, upgrade it to version 6.3.8359.
- If the “windows app” component is installed, upgrade it to version 2.0.1314.0.
- If you cannot patch right away, restrict network access to HPC Pack entry points (allow only required admin/compute traffic) and closely monitor for unusual inbound requests targeting HPC services.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- Microsoft выпустила патчи более чем для 400 уязвимостейru-ru·Хакер (xakep.ru)· Exploited Windows Lazarus
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attacken·The Hacker News· Exploited Windows Lazarus Group
- August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Dayen-us·SecurityWeek· Exploited Windows Lazarus group
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-59124 and every CVE in our database. Create a free account — no credit card required.
Create Free Account