Product
An unauthenticated RCE vulnerability in winml-cli (CVE-2026-84452) allows remote attackers to execute arbitrary code via a malicious website sending cross-origin requests to the local API server.