CVE-2026-59124ImportantRevised 16 Aug
Microsoft High Performance Computing (HPC) Pack Remote Code Execution Vulnerability
Assessment
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
- Severity
- Important
- CVSS base score
- 9.8CVSS:3.1/
AV:N/ AC:L/ PR:N/ UI:N/ S:U/ C:H/ I:H/ A:H/ E:U/ RL:O/ RC:C - Impact
- Remote Code Execution
- EPSS, next 30 days
- 1.5%Higher than 73.8% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Exploitation More Likely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Microsoft High Performance Computing (HPC) Pack
- Weakness
- CWE-502: Deserialization of Untrusted Data
- Issued by
- Microsoft
- Published
- 11 Aug 2026 · August 2026
- Last revised
- 16 Aug 2026Corrected the listed software in the Security Updates table. Microsoft recommends installing the security update as soon as possible.
Updates that fix it
0 KBsNo KB listed
MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.
Affected products
Azure1 affected product
- Microsoft HPC Pack 2019