Microsoft Security Response Center Follow CVE-2026-38754 A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-38754 msrc.microsoft.com