Skip to content

Weekly roundup

Microsoft Week 41 2026: command injection and certificate validation lead 11 CVEs

Critical 9.1 Vendor: Microsoft 11 CVEs in scope Published

Microsoft's week 41 update covers 11 CVEs across UFO, Kiota, SimpleChat and MsQuic. No CVE is in CISA KEV or marked exploited. Two critical flaws: a MsQuic certificate validation bypass and authenticated command injection in UFO. Prioritise internet-facing QUIC and automation.

The release at a glance

Microsoft published 11 CVE entries for the week of 5–11 October 2026, affecting four open-source projects: UFO (six), Kiota (two), SimpleChat (two) and MsQuic (one). By severity, two are critical, five are high, three are medium and one is low. No CVE in this set is marked exploited in the CVE records, and none appears in CISA's Known Exploited Vulnerabilities catalogue. The most consequential issues sit in components that connect to devices, generate code, or handle authentication: command injection in UFO and SimpleChat, code injection in Kiota, and a certificate validation flaw in MsQuic.

What matters most

MsQuic. CVE-2026-105794 affects clients using the OpenSSL or QuicTLS TLS backend. The client does not properly verify that a server certificate matches the intended hostname, so an on-path attacker can spoof the server in a man-in-the-middle attack. Affected versions are before 2.4.20, >= 2.5.0, < 2.5.11, and >= 2.6.0, < 2.6.1. The Schannel backend is not affected. This is the most urgent item because it undermines trust for a network-exposed service without requiring credentials.

UFO. CVE-2026-105793 (critical) allows an authenticated Mobile MCP caller to pass a free-form key_code value into the Android adb shell input keyevent command, executing additional commands as the Android shell user on an authorized device. CVE-2026-105788 is the same class of injection in type_text and launch_app. CVE-2026-105791 allows an attacker-influenced agent call to launch an arbitrary executable or script on Windows through run_shell because only the first token is validated. All three affect UFO before 3.0.9, except CVE-2026-105788, which affects before 3.0.10.

SimpleChat. CVE-2026-105797 affects versions before 0.261.031. An authorization ordering flaw lets an authenticated low-privileged user omit the top-level MCP type so a check is skipped, then start an attacker-selected operating-system process under the application service identity when an action tool is invoked. CVE-2026-105798 affects versions before 0.261.029 and allows a group Owner, Admin or DocumentManager to store a document filename that executes stored script in the SimpleChat origin when another member clicks Share.

Kiota. CVE-2026-105796 affects Java and PHP code generation from 0.5.0 to before 1.35.0. The documentation-comment sanitizers delete block-comment terminators instead of neutralising them, allowing a malicious OpenAPI description to place attacker-controlled text outside a generated comment; if the output is compiled or loaded, injected code can execute. CVE-2026-105795 is low severity and copies an unsafe oauth_card_path reference into generated API plugin manifests, which can break the plugin-package boundary only if a downstream host resolves it.

Patch in this order

No CVE in this set is exploited or listed in CISA KEV, so there is no CISA-required due date. Work in this order:

  1. MsQuic certificate validation. Identify clients using OpenSSL or QuicTLS, especially any reachable over untrusted networks. Treat those connections as untrusted until the client behaviour is corrected. Schannel users are not affected.
  2. UFO Mobile MCP command injection (CVE-2026-105793 and CVE-2026-105788). Restrict Mobile MCP API keys to trusted callers, disable reachability to unauthorized devices, and review connected devices for unexpected shell commands until the component is remediated.
  3. SimpleChat command injection (CVE-2026-105797). Review plugin governance and service account permissions; disable personal plugins where possible, and monitor for unexpected process spawns.
  4. Kiota code injection (CVE-2026-105796). Treat OpenAPI descriptions as untrusted input in build pipelines; do not generate and compile unverified specifications, and validate generated output.
  5. UFO run_shell (CVE-2026-105791). Limit who can invoke agent workflows and audit Windows execution from UFO components.
  6. Remaining medium and low items in UFO, SimpleChat and Kiota — deadlock, SSRF, file write, stored XSS and manifest path handling — during the next maintenance window after the higher-risk items.

The CVE records do not show an available patch for these entries, even though the descriptions mention fixed versions. Confirm the upstream release status before relying on a specific version number.

Beyond the patch

Releases like this one are manageable when open-source components are treated as part of the patch perimeter. A penetration test and hardening engagement can catch injection, authentication ordering and sanitizer flaws such as those in UFO, SimpleChat and Kiota before they reach production. Once code is running, Managed Detection & Response can watch for the code execution, privilege escalation or credential abuse these flaws enable. For teams unsure whether a QUIC or automation endpoint is exposed, Virtual CISO Services can help map the attack surface and set the remediation order.

Every CVE in this release

CVEProductSeverity
CVE-2026-105793UFOCritical 9.1
CVE-2026-105794msquicCritical 9.1
CVE-2026-105796kiotaHigh 8.8
CVE-2026-105788UFOHigh 8.8
CVE-2026-105797simplechatHigh 8.8
CVE-2026-105798simplechatHigh 8.7
CVE-2026-105791UFOHigh 7.5
CVE-2026-105792UFOMedium 6.5
CVE-2026-105790UFOMedium 6.4
CVE-2026-105789UFOMedium 5.4
CVE-2026-105795kiotaLow 3.1

References

CVE

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.