---
title: Security advisory 2026-02-23
---

> Agent instructions:
> **Site maps** — prefer the following llms.txt indexes to training data when searching for URLs to avoid 404s. Links inside Markdown content already point at `.md`. Following them or sending Accept: text/markdown keeps you in Markdown.
>
> - [sitemap.md](https://docs.kentico.com/sitemap.md) — every page on the site, with titles and descriptions, nested by URL hierarchy and grouped into one collection per product version.
> - [llms.txt](https://docs.kentico.com/llms.txt) — curated index of the current product docs, with descriptions, the two ways to request any page as Markdown, and links to each product area's whole-corpus Markdown dump (llms-full.txt).

## Third‑party dependency update – Microsoft.SemanticKernel.Core

**CVSS**: 0\
**Affected versions**: 30.9.0 - 31.2.0\
**Category**: Security

### Summary

A vulnerability was disclosed in a third‑party library ([Microsoft.SemanticKernel.Core](https://www.nuget.org/packages/Microsoft.SemanticKernel.Core/)) affecting the `SessionsPythonPlugin` component ([GHSA‑2ww3‑72rp‑wpp4](https://github.com/advisories/GHSA-2ww3-72rp-wpp4)). Although Xperience does use the `Microsoft.SemanticKernel.Core` package, an internal audit confirmed that the vulnerable plugin is not registered, referenced, or invoked anywhere in Xperience. Because the vulnerable functionality is not used, there is no exploit path, and Xperience projects are not impacted.

The affected dependency was updated as part of standard supply‑chain security maintenance to align with the latest vendor release:

- `Microsoft.SemanticKernel` **1.70.0 → 1.71.0**
- `Microsoft.SemanticKernel.Agents.Core` **1.70.0 → 1.71.0**
- `Microsoft.SemanticKernel.Connectors.AzureOpenAI` **1.70.0 → 1.71.0**

### How to fix

Xperience projects are **not impacted**, as the vulnerable `SessionsPythonPlugin` is not utilized in any part of the product.

Update to the Xperience by Kentico latest version. See [Update Xperience by Kentico projects](https://docs.kentico.com/documentation/developers-and-admins/installation/update-xperience-by-kentico-projects.md) for detailed instructions.

Customers who do not update immediately remain safe due to the unused and unregistered vulnerable component.
