SYS::ONLINE
Wasteland.
Briefs1674
Issues21
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-26142 2026-06-09

CVE-2026-26142: Critical Deserialization RCE in Nuance PowerScribe

"A critical (CVSS 9.8) insecure-deserialization flaw in Nuance PowerScribe lets an unauthenticated attacker run arbitrary code over the network."

A critical (CVSS 9.8) insecure-deserialization flaw in Nuance PowerScribe lets an unauthenticated attacker run arbitrary code over the network.

What Is It

CVE-2026-26142 is a deserialization-of-untrusted-data vulnerability (CWE-502) in Nuance PowerScribe. According to the NVD record, the flaw "allows an unauthorized attacker to execute code over a network." It was published on June 9, 2026, with Microsoft ([email protected]) as the assigning source, and currently carries a vulnerability status of "Awaiting Analysis."

Why It Matters

The vulnerability is rated CRITICAL with a CVSS 3.1 base score of 9.8. Its vector, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicates the worst-case exploitability profile: it is reachable over the network, requires low attack complexity, needs no privileges, and requires no user interaction. A successful exploit yields high impact to confidentiality, integrity, and availability, meaning an attacker could achieve full remote code execution without authenticating.

What's Vulnerable

The affected product is Nuance PowerScribe. The supplied data does not enumerate specific affected versions or CPE entries, so exact version coverage is not available from this source material.

Patch Status

The supplied source material does not include a CISA KEV entry for this CVE, so there is no confirmation of active exploitation in the provided data. The NVD record references Microsoft's Security Update Guide for remediation details. Organizations should consult that advisory for patch and mitigation guidance.

Sources