Microsoft Data Formulator Remote Code Execution Vulnerability

Vulnerability

A code injection vulnerability has been identified in Microsoft Data Formulator, allowing unauthorized attackers to execute code remotely over a network. This issue arises from improper control of code generation, which could be exploited by manipulating user-supplied input that is processed by the affected application.

Impact

Exploitation of this vulnerability allows for remote code execution on the affected system.

Remediation

Users can download the security update for Microsoft Data Formulator from the Python Package Index (PyPI).

Added: May 12, 2026, 7:23 PM
Updated: May 12, 2026, 7:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.4
remediation
0.0
relevance
8.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.