CVE-2026-54120 Microsoft Surface Remote Code Execution Vulnerability Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network. EPSS 0.01 CVE-2026-54120 Microsoft US Microsoft Security · 23. 7. 16:00