CVE-2026-2256 is a vulnerability tracked across 1 threat cluster and 2 intelligence report mentions on ThreatCluster. First observed March 2, 2026; most recent activity March 3, 2026.
A command injection vulnerability was identified in the MS-Agent framework, allowing attackers to exploit improper input sanitization through its shell tool. This flaw can lead to arbitrary command execution on systems…