type: cve ยท created: 2026-08-12 ยท updated: 2026-08-12 ยท tags: [cve, rce, microsoft, hpc-pack, unauthenticated, patch-tuesday] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, defence, education] ยท au_impact: false
CVE-2026-59124 โ Microsoft HPC Pack RCE
CVE-2026-59124 is an unauthenticated remote code execution (RCE) vulnerability in Microsoft HPC Pack, rated CVSS 9.8, shipped in Microsoft's August 2026 Patch Tuesday release (2026-08-11) alongside three other unauthenticated RCEs in Windows components.
Vulnerability Details
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-59124 |
| Type | Unauthenticated remote code execution (RCE) |
| Product | Microsoft HPC Pack |
| Access | Unauthenticated |
| CVSS | 9.8 |
| Exploitation status | Not flagged as actively exploited in the wild in the August 2026 release |
Context
The flaw was patched in Microsoft's August 2026 Patch Tuesday, the company's largest monthly release in years (398 CVEs, 62 rated Critical per ZDI). CVE-2026-59124 is one of four unauthenticated RCE flaws at CVSS 9.8 in that release, alongside vulnerabilities in Windows DNS Server, Windows Deployment Services and Microsoft's QUIC stack.
Mitigation
- Apply the August 2026 Windows security updates promptly
- Prioritise patching under the ACSC Essential Eight patching schedule if HPC Pack is deployed
Sources: raw/digests/Cyber-Digest-2026-08-12