A critical (CVSS 9.8) insecure-deserialization flaw in Nuance PowerScribe lets an unauthenticated attacker run arbitrary code over the network.
What Is It
CVE-2026-26142 is a deserialization-of-untrusted-data vulnerability (CWE-502) in Nuance PowerScribe. According to the NVD record, the flaw "allows an unauthorized attacker to execute code over a network." It was published on June 9, 2026, with Microsoft ([email protected]) as the assigning source, and currently carries a vulnerability status of "Awaiting Analysis."
Why It Matters
The vulnerability is rated CRITICAL with a CVSS 3.1 base score of 9.8. Its vector, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicates the worst-case exploitability profile: it is reachable over the network, requires low attack complexity, needs no privileges, and requires no user interaction. A successful exploit yields high impact to confidentiality, integrity, and availability, meaning an attacker could achieve full remote code execution without authenticating.
What's Vulnerable
The affected product is Nuance PowerScribe. The supplied data does not enumerate specific affected versions or CPE entries, so exact version coverage is not available from this source material.
Patch Status
The supplied source material does not include a CISA KEV entry for this CVE, so there is no confirmation of active exploitation in the provided data. The NVD record references Microsoft's Security Update Guide for remediation details. Organizations should consult that advisory for patch and mitigation guidance.