CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-72971

mediumCVSS 5.5covered by 3 sourcesfirst seen 2026-08-11
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.

CSIRTS triage

What
Link following vulnerability in unionfs.sys allows an authorized attacker to perform tampering locally.
Who is affected
Windows Container environments with unpatched unionfs.sys are affected.
Urgency
Medium priority; local tampering vulnerability not currently exploited but affects authenticated users.
Action
Apply the latest Windows Container security update.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-72971

Get an email if CVE-2026-72971 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-72971

CVE.org record

Embed the live status

CVE-2026-72971 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-72971 status](https://www.csirts.com/badge/CVE-2026-72971)](https://www.csirts.com/cve/CVE-2026-72971)