You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2026-26142
About this tag
CVE-2026-26142 is a critical remote code execution vulnerability in Nuance PowerScribe and PowerScribe One, disclosed by Microsoft on June 9, 2026. The flaw stems from unsafe deserialization, allowing an unauthenticated network attacker to execute arbitrary code on affected systems. This server-side vulnerability poses significant risks in healthcare environments where PowerScribe is used for radiology reporting, as it can compromise clinical workflows, dictation systems, and patient data. Immediate patching is essential to mitigate exposure. Discussions on WindowsForum emphasize the severity of this issue and the need for urgent action.
Microsoft disclosed CVE-2026-26142 on June 9, 2026, as a critical remote code execution flaw in Nuance PowerScribe and PowerScribe One caused by unsafe deserialization, allowing an unauthenticated network attacker to run code if affected systems remain exposed and unpatched in healthcare...