CVE-2026-55015
An attacker can exploit multiple vulnerabilities in Microsoft Windows Server 2012 R2, Windows Server 2012, Windows Server 2016, Windows 10, Windows 11, Windows Server 2025, Windows Server 2022, Windows Server 2019, Microsoft Windows Remote Help and Windows App for Mac to gain administrator rights, conduct spoofing attacks, disclose confidential information or trigger a Denial-of-Service condition.
CSIRTS triage
- What
- Multiple vulnerabilities in Microsoft Windows Services allow attackers to gain administrator rights, conduct spoofing, disclose confidential information, or trigger denial of service.
- Who is affected
- Deployments running Windows Server 2012 R2, 2012, 2016, 2019, 2022, 2025, Windows 10, Windows 11, Windows Remote Help, and Windows App for Mac are affected.
- Urgency
- Medium urgency; multiple vectors including privilege escalation and information disclosure affect widely deployed systems, though not currently exploited.
- Action
- Apply Windows security updates covering CVE-2026-55013, CVE-2026-55015, CVE-2026-62727, and CVE-2026-69550.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-55015
Get an email if CVE-2026-55015 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
Advisory coverage (4)
- medium[NEW] [medium] Microsoft Windows Services: Multiple Vulnerabilitiescert-bund · 2026-08-21
- unknownMultiple vulnerabilities in Microsoft products (August 21, 2026)cert-fr-avis · 2026-08-21
- mediumCVE-2026-55015: Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny …nvd · 2026-08-20
- mediumCVE-2026-55015: Microsoft Remote Help Denial of Service Vulnerabilitymsrc · 2026-08-11
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-55015)