Microsoft disclosed and coordinated fixes for command injection vulnerabilities affecting Visual Studio Code and the Azure azure-cli-mcp component, with both flaws allowing arbitrary code execution through improper validation of user-supplied input before it is passed to a system call. In Visual Studio Code, tracked as CVE-2026-21518 and ZDI-26-253, a remote attacker can achieve code execution in the context of the current user if a victim opens a malicious project containing a crafted mcp.json file; the issue was assigned a CVSS 7.8 rating and patched by Microsoft.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Microsoft patched and publicly disclosed the Visual Studio Code command injection flaw as CVE-2026-21518 in a coordinated advisory release. The vulnerability, tracked by ZDI as ZDI-26-253 / ZDI-CAN-29184, received a CVSS score of 7.8.
ZDI publicly disclosed the critical Azure command injection vulnerability as ZDI-26-226 / ZDI-CAN-28042. The issue was described as unauthenticated remote code execution in the context of the MCP server and assigned a CVSS score of 9.8.
Zero Day Initiative informed Microsoft that it intended to publicly disclose the Azure azure-cli-mcp vulnerability as a zero-day. This marked an escalation in the disclosure process after vendor coordination.
TrendAI Research reported a command injection vulnerability in Microsoft Visual Studio Code involving malicious mcp.json files to Microsoft. Opening a crafted project could allow arbitrary code execution in the context of the current user.
Trend Micro's Zero Day Initiative reported a command injection vulnerability in Microsoft Azure's azure-cli-mcp component to Microsoft. The flaw could allow unauthenticated remote attackers to execute arbitrary code over the network.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.