DIRAS TAKE
Urgent: public exploit code exists, so prioritize patching systems; apply the vendor fixes or block untrusted local accounts immediately.
What is CVE-2026-50402?
Local users with low privileges can elevate to higher privileges on Windows systems due to an incorrect numeric type conversion in NTFS. CVE-2026-50402 affects multiple Windows branches (see affected list) including Windows 10 Version 1607 and later listed entries; required conditions are local access and a low-privilege account (no user interaction required). The vulnerability can lead to full confidentiality, integrity, and availability impact on affected machines.
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1607 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9339 | 10.0.14393.9339 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9020 | 10.0.17763.9020 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7548 | 10.0.19044.7548 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7548 | 10.0.19045.7548 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.8875 | 10.0.26100.8875 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.8875 | 10.0.26200.8875 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2525 | 10.0.28000.2525 |
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26226 | 6.2.9200.26226 |
| Windows Server 2012 (Server Core installation) 6.x | 6.2.9200.0 – before 6.2.9200.26226 | 6.2.9200.26226 |
| Windows Server 2012 R2 6.x | 6.3.9600.0 – before 6.3.9600.23291 | 6.3.9600.23291 |
Is CVE-2026-50402 being exploited?
Public exploit code is available.
How to fix CVE-2026-50402
- Install Microsoft updates that move affected builds to the fixed versions listed (for example 10.0.14393.9339, 10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548, 10.0.26100.8875, 10.0.26200.8875, 10.0.28000.2525, 6.2.9200.26226, 6.3.9600.23291).
- Restrict and audit local accounts and limit who can log on interactively to affected hosts.
- Monitor systems for unusual privilege usage and review security event logs for escalation attempts.
- Follow Microsoft's guidance and deploy updates via your normal patch management processes.
Frequently asked questions
Is CVE-2026-50402 being actively exploited?
Public exploit code is available for CVE-2026-50402.
Which Windows versions are affected by CVE-2026-50402?
Affected versions include multiple Windows branches listed by Microsoft, such as Windows 10 Version 1607 (builds before 10.0.14393.9339) and additional Windows 10, Windows 11, and Windows Server builds shown in the affected list.
Is there a patch for CVE-2026-50402?
Yes; Microsoft published fixes that raise affected builds to the fixed versions named in the advisory (see affected[].fixed for exact build numbers).
Does CVE-2026-50402 require authentication?
Yes; the issue requires a local low-privilege account to exploit and does not require user interaction.
References
- nvd.nist.gov/vuln/detail/CVE-2026-50402
- cve.org/CVERecord?id=CVE-2026-50402
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50402
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026