
Microsoft CEO Satya Nadella said in a memo to Microsoft's employees:
If you’re faced with the tradeoff between security and another priority, your answer is clear: Do security. In some cases, this will mean prioritizing security above other things we do, such as releasing new features or providing ongoing support for legacy systems. This is key to advancing both our platform quality and capability such that we can protect the digital estates of our customers and build a safer world for all.
This market resolves when a security issue is discovered in a Microsoft product where it is reasonably obvious that if security had been prioritized as the memo commands, the issue would have been avoided. (If there is enough doubt, a poll will be created to decide)
https://www.theverge.com/24148033/satya-nadella-microsoft-security-memo
CVE-2026-20841 looked like a possible candidate but it's unclear if this code was added after the memo was issued. Is there an easy way to cross-reference CVEs and software releases to find a CVE that only applies to versions released after the memo?