Back to overview

CVE-2026-26142

CRITICAL
9.8
CVSS 3.1

Metadata

CVE ID
CVE-2026-26142
State
PUBLISHED
Assigner
microsoft
Reserved
2026-02-11 16:24 UTC
Published
2026-06-09 17:05 UTC
Last updated
2026-07-28 22:19 UTC
Primary CWE
CWE-502
CWE-502: Deserialization of Untrusted Data
Vendor / Product
Microsoft / Nuance PowerScribe 360 4.0
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (22)
VendorProductPlatformVersions
Microsoft Nuance PowerScribe 360 4.0 — 4.0 < 7.0.11.49
Microsoft Nuance PowerScribe 360 version 4.0.1 — 4.0.1 < 7.0.111.68
Microsoft Nuance PowerScribe 360 version 4.0.2 — 4.0.2 < 7.0.154.18
Microsoft Nuance PowerScribe 360 version 4.0.3 — 4.0.3 < 7.0.197.10
Microsoft Nuance PowerScribe 360 version 4.0.4 — 4.0.4 < 7.0.212.10
Microsoft Nuance PowerScribe 360 version 4.0.5 — 4.0.5 < 7.0.243.19
Microsoft Nuance PowerScribe 360 version 4.0.6 — 4.0.6 < 7.0.277.28
Microsoft Nuance PowerScribe 360 version 4.0.7 — 4.0.7 < 7.0.316.12
Microsoft Nuance PowerScribe 360 version 4.0.8 — 4.0.8 < 7.0.427.15
Microsoft Nuance PowerScribe 360 version 4.0.9 — 4.0.9 < 7.0.528.24
Microsoft Nuance PowerScribe One version 2019.1 — 2019.1 < 2019.1.96.6
Microsoft Nuance PowerScribe One version 2019.10 — 2019.10 < 2019.10.36.14
Microsoft Nuance PowerScribe One version 2019.2 — 2019.2 < 2019.2.9.11
Microsoft Nuance PowerScribe One version 2019.3 — 2019.3 < 2019.3.16.21
Microsoft Nuance PowerScribe One version 2019.4 — 2019.4 < 2019.4.9.17
Microsoft Nuance PowerScribe One version 2019.5 — 2019.5 < 2019.5.14.40
Microsoft Nuance PowerScribe One version 2019.6 — 2019.6 < 2019.6.36.40
Microsoft Nuance PowerScribe One version 2019.7 — 2019.7 < 2019.7.107.26
Microsoft Nuance PowerScribe One version 2019.8 — 2019.8 < 2019.8.43.19
Microsoft Nuance PowerScribe One version 2019.9 — 2019.9 < 2019.9.31.23
Microsoft PowerScribe One version 2023.1 SP2 Patch 11 — 2023.1 < 2023.2.3054
Microsoft PowerScribe One version 2023.1 SP3 Patch 6 — 2023.1 < 2023.3.9072
Weakness (CWE)
CWESourceDescription
CWE-502 cna CWE-502: Deserialization of Untrusted Data
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
References (1)
Back to overview