Microsoft has disclosed CVE-2026-54120, a critical (CVSS 9.9) improper input validation vulnerability in Microsoft Surface Management Services that allows an authorized attacker to execute code over a network.
What Is It
CVE-2026-54120 is an improper input validation weakness (CWE-20) in Microsoft Surface. According to Microsoft's disclosure, the flaw "allows an authorized attacker to execute code over a network." It was published on July 23, 2026, and is currently in "Received" status at NVD, sourced from Microsoft's security response team.
Why It Matters
The vulnerability carries a CVSS 3.1 base score of 9.9 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Several factors drive that severity: the attack is network-based (AV:N) with low complexity (AC:L), requires no user interaction (UI:N), and needs only low privileges (PR:L). Critically, the scope is Changed (S:C), meaning a successful exploit can affect resources beyond the vulnerable component's security boundary. Confidentiality, integrity, and availability impacts are all rated High, indicating a full compromise scenario for affected systems.
Note: No CISA KEV entry accompanied this disclosure, so active exploitation is not confirmed in the supplied source material.
What's Vulnerable
The affected product is Microsoft Surface Management Services (vendor: Microsoft). Microsoft tags this CVE as an "exclusively-hosted-service," and the affected version is listed as "-" (unspecified). No specific affected CPE configurations were provided in the NVD record.
Patch Status
Microsoft has published guidance through its Security Update Guide. Because this is flagged as an exclusively hosted service, remediation is typically managed on the vendor side. Administrators should consult the Microsoft MSRC update guide entry (linked below) for the authoritative required action and remediation details. No separate CISA-required action or due date was present in the supplied data.