[NEW] [medium] Microsoft Windows Services: Multiple Vulnerabilities
An attacker can exploit multiple vulnerabilities in Microsoft Windows Server 2012 R2, Windows Server 2012, Windows Server 2016, Windows 10, Windows 11, Windows Server 2025, Windows Server 2022, Windows Server 2019, Microsoft Windows Remote Help and Windows App for Mac to gain administrator rights, conduct spoofing attacks, disclose confidential information or trigger a Denial-of-Service condition.
CSIRTS triage
- What
- Multiple vulnerabilities in Microsoft Windows Services allow attackers to gain administrator rights, conduct spoofing, disclose confidential information, or trigger denial of service.
- Who is affected
- Deployments running Windows Server 2012 R2, 2012, 2016, 2019, 2022, 2025, Windows 10, Windows 11, Windows Remote Help, and Windows App for Mac are affected.
- Urgency
- Medium urgency; multiple vectors including privilege escalation and information disclosure affect widely deployed systems, though not currently exploited.
- Action
- Apply Windows security updates covering CVE-2026-55013, CVE-2026-55015, CVE-2026-62727, and CVE-2026-69550.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Windows Services
Get an email when a new Windows Services advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2947
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-550130.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-550150.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-627270.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-695500.69% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-55013 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-55015 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-62727 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-69550 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple vulnerabilities in Microsoft products (August 21, 2026)cert-fr-avis
- mediumCVE-2026-55015: Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny …nvd
- highCVE-2026-55013: Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker …nvd
- unknownMultiple vulnerabilities in Microsoft Windows (20 August 2026)cert-fr-avis
- mediumCVE-2026-69550: Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose inform…nvd
- highCVE-2026-62727: Concurrent execution using shared resource with improper synchronization ('race condition') in…nvd
- mediumCVE-2026-55015: Microsoft Remote Help Denial of Service Vulnerabilitymsrc
- mediumCVE-2026-69550: Windows App for Mac Information Disclosure Vulnerabilitymsrc
- highCVE-2026-55013: Windows Remote Help Defense Spoofing Vulnerabilitymsrc
- highCVE-2026-62727: Windows Telephony Service Elevation of Privilege Vulnerabilitymsrc
Recent advisories for Microsoft Windows Services
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-66804: Microsoft Windows Cross Device Service Elevation of Privilege Vulnerabilitymsrc · 2026-08-11
- mediumCVE-2026-42915: Microsoft Windows VMSwitch Denial of Service Vulnerabilitymsrc · 2026-06-09
- criticalexploitedCVE-2025-59287: Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerabilitycisa-kev · 2025-10-24
- criticalexploitedCVE-2024-26169: Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerabilitycisa-kev · 2024-06-13
- criticalexploitedCVE-2023-28229: Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerabilitycisa-kev · 2023-10-04
- criticalexploitedCVE-2023-36874: Microsoft Windows Error Reporting Service Privilege Escalation Vulnerabilitycisa-kev · 2023-07-11
More from CERT-Bund (BSI) Security Advisories
- medium[NEW] [medium] Langflow: Multiple vulnerabilities2026-09-04
- medium[NEW] [medium] Grafana Enterprise: Multiple vulnerabilities allow gaining user or administrator privileges2026-09-04
- low[NEW] [low] Checkmk: Vulnerability allows Denial of Service2026-09-04
- low[NEW] [low] ImageMagick: Multiple vulnerabilities allow Denial of Service2026-09-04
- critical[NEW] [critical] vm2: Multiple vulnerabilities allow code execution2026-09-04