[NEW] [critical] Microsoft Windows products: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Microsoft Windows products to escalate privileges, execute arbitrary code, conduct a Denial of Service attack, disclose information, present false information, manipulate data, and bypass security measures.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to escalate privileges, execute arbitrary code, conduct Denial of Service attacks, and manipulate data.
- Who is affected
- All deployments of Microsoft Windows products are affected.
- Urgency
- Remediation is urgent due to the critical severity of the vulnerabilities.
- Action
- Apply the latest security updates from Microsoft.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Windows
Get an email when a new Windows advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2316
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-503470.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all scored CVEs.
- Low exploitation riskCVE-2026-503120.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all scored CVEs.
- Low exploitation riskCVE-2026-503210.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all scored CVEs.
- Low exploitation riskCVE-2026-503700.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all scored CVEs.
- Low exploitation riskCVE-2026-504190.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all scored CVEs.
- Low exploitation riskCVE-2026-503410.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all scored CVEs.
- Low exploitation riskCVE-2026-503800.63% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all scored CVEs.
- Moderate exploitation riskCVE-2026-503301.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 63% of all scored CVEs.
- Low exploitation riskCVE-2026-503130.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all scored CVEs.
- Low exploitation riskCVE-2026-503680.78% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 52% of all scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-50505: Use after free in Windows Message Queuing allows an authorized attacker to execute code over a…nvd
- highCVE-2026-50502: Insufficient granularity of access control in Windows Event Logging Service allows an authoriz…nvd
- highCVE-2026-50500: Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a …nvd
- highCVE-2026-50498: Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerabilitynvd
- highCVE-2026-50494: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code local…nvd
- highCVE-2026-50491: Out-of-bounds read in Code Integrity DLL (ci.dll) allows an authorized attacker to elevate pri…nvd
- highCVE-2026-50490: Use after free in Windows Installer allows an authorized attacker to elevate privileges locall…nvd
- highCVE-2026-50489: Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileg…nvd
- mediumCVE-2026-50485: Buffer over-read in Windows Hyper-V allows an authorized attacker to deny service over an adja…nvd
- highCVE-2026-50482: Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code local…nvd
- highCVE-2026-50480: Heap-based buffer overflow in Windows Web Proxy Auto-Discovery Protocol (WPAD) allows an autho…nvd
- highCVE-2026-50477: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileg…nvd
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow unspecified attack2026-07-31