CVE-2026-2256 - Vulnerability Details

Threat entity extracted from intelligence sources

Frequency
2
occurrences
First Seen
March 2, 2026
Last Seen
March 3, 2026

CVE-2026-2256 is a vulnerability tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed March 2, 2026; most recent activity March 3, 2026.

Related Threat Clusters

  • Command Injection Vulnerability in MS-Agent Framework Discovered

    A command injection vulnerability was identified in the MS-Agent framework, allowing attackers to exploit improper input sanitization through its shell tool. This flaw can lead to arbitrary command execution on systems…

    7 articles · Updated March 3, 2026

Recent Intelligence Reports

  • Critical MS — Cyberpress · March 3, 2026
  • VU#431821: MS-Agent does not properly sanitize commands sent to its shell tool, allowing for RCE — Kb.Cert · March 2, 2026

CVSS v3.1 Breakdown