DIRAS TAKE
Urgent: public exploit code exists, so prioritize updates. Microsoft published fixed builds for each affected branch; apply them or block local access where possible.
What is CVE-2026-49176?
An authorized local user can gain elevated privileges on Windows 10, Windows 11, and affected Windows Server builds via an improper privilege management bug in the WalletService (CVE-2026-49176). Affected builds include Windows 10 Version 1607 (10.0.14393.0 before 10.0.14393.9339), Version 1809 (10.0.17763.0 before 10.0.17763.9020), 21H2 and 22H2 (10.0.19044.0 and 10.0.19045.0 before 10.0.19044.7548 and 10.0.19045.7548), and several Windows 11 and Server branches listed in vendor guidance; an attacker requires local, authorized (non‑elevated) access to exploit the flaw. The weakness is classified as CWE-269 (Improper Privilege Management).
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1607 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9339 | 10.0.14393.9339 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9020 | 10.0.17763.9020 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7548 | 10.0.19044.7548 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7548 | 10.0.19045.7548 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.8875 | 10.0.26100.8875 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.8875 | 10.0.26200.8875 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2525 | 10.0.28000.2525 |
| Windows Server 2016 10.x | 10.0.14393.0 – before 10.0.14393.9339 | 10.0.14393.9339 |
| Windows Server 2016 (Server Core installation) 10.x | 10.0.14393.0 – before 10.0.14393.9339 | 10.0.14393.9339 |
| Windows Server 2019 10.x | 10.0.17763.0 – before 10.0.17763.9020 | 10.0.17763.9020 |
Is CVE-2026-49176 being exploited?
Public exploit code is available.
How to fix CVE-2026-49176
- Install the Microsoft fixed builds: 10.0.14393.9339, 10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548, 10.0.26100.8875, 10.0.26200.8875, 10.0.28000.2525 as applicable to your branch.
- Restrict local account access and remove or disable unnecessary local accounts on affected systems.
- Monitor endpoint logs for unusual privilege escalations and suspicious process activity tied to WalletService.
- Apply vendor guidance and follow standard hardening and least-privilege policies until updates are deployed.
Frequently asked questions
Is CVE-2026-49176 being actively exploited?
Public exploit code for CVE-2026-49176 is available, though it is not listed in the CISA Known Exploited Vulnerabilities catalog as of 2026-09-29.
Which Windows versions are affected by CVE-2026-49176?
Windows 10, several Windows 11 branches and Windows Server builds are affected; examples include Windows 10 Version 1607 (10.0.14393.0 through before 10.0.14393.9339) and Version 1809 (10.0.17763.0 through before 10.0.17763.9020). Refer to the vendor affected list for full build ranges.
Is there a patch for CVE-2026-49176?
Yes. Microsoft published fixed builds for each affected branch, for example 10.0.14393.9339, 10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548, 10.0.26100.8875, 10.0.26200.8875 and 10.0.28000.2525.
Does CVE-2026-49176 require authentication?
Yes. Exploitation requires a local, authorized (non‑elevated) user account on the affected Windows system.
References
- nvd.nist.gov/vuln/detail/CVE-2026-49176
- cve.org/CVERecord?id=CVE-2026-49176
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49176
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026