HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Remote Code Execution in Microsoft PowerShell (CVE‑2026‑40400) via Help Directory Traversal

A directory‑traversal bug in PowerShell module help files (CVE‑2026‑40400) enables remote code execution with user interaction. The issue underscores the need for robust configuration‑management and patch‑evidence practices to satisfy SOC 2 audit requirements.

LiveThreat™ Intelligence · 📅 July 16, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Critical Remote Code Execution in Microsoft PowerShell (CVE‑2026‑40400) via Help Directory Traversal

What It Is — A directory‑traversal flaw in the parsing of PowerShell module help files allows an attacker to execute arbitrary code on the host running PowerShell. The vulnerability is tracked as CVE‑2026‑40400 and carries a CVSS 7.8 (High) rating.

Exploitability — Exploits require user interaction (the victim must open a malicious page or file), but a working proof‑of‑concept exists and Microsoft has already released a security update.

Affected Products — Microsoft PowerShell (all supported versions at the time of disclosure).

Why It Matters for Compliance & Audit Readiness

  • Control Mapping – The flaw highlights gaps in configuration‑management and change‑control processes that map to SOC 2 CC6.1 (System Operations) and CC7.2 (Change Management).
  • Evidence of Due Diligence – Demonstrating timely patch deployment and documented remediation provides audit‑ready evidence of a mature vulnerability‑management program, a key expectation of enterprise buyers.
  • Continuous Monitoring – Ongoing verification that the PowerShell update remains applied across all assets supports continuous compliance monitoring and reduces the risk of control failures during an audit.

Recommended Actions

  • Deploy Microsoft’s patch for CVE‑2026‑40400 immediately on all PowerShell‑enabled systems.
  • Verify the patch status through automated inventory tools and capture screenshots or logs as audit evidence.
  • Update your configuration‑management policies to require validation of module help files and enforce least‑privilege execution contexts.
  • Map the remediation to the relevant SOC 2 controls in your compliance framework and record the remediation workflow in your GRC platform.

Source: Zero Day Initiative Advisory – ZDI‑26‑414

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-414/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →