DIRAS TAKE
Urgent: public exploit code exists for this Win32K race condition, so prioritize installing the vendor updates that move affected builds to the fixed builds listed by Microsoft.
What is CVE-2026-54107?
An authorized local user can elevate privileges on Windows systems due to a race condition in the Win32K component (CVE-2026-54107). The flaw affects Windows 10 Version 1607 and multiple other Windows 10, Windows 11 and Windows Server branches; affected builds are listed by vendor and are fixed at specific build numbers. An attacker needs local access with an account on the target host to trigger the improper synchronization and gain higher privileges.
Vector CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1607 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9339 | 10.0.14393.9339 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9020 | 10.0.17763.9020 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7548 | 10.0.19044.7548 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7548 | 10.0.19045.7548 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.8875 | 10.0.26100.8875 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.8875 | 10.0.26200.8875 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2525 | 10.0.28000.2525 |
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26226 | 6.2.9200.26226 |
| Windows Server 2012 (Server Core installation) 6.x | 6.2.9200.0 – before 6.2.9200.26226 | 6.2.9200.26226 |
| Windows Server 2012 R2 6.x | 6.3.9600.0 – before 6.3.9600.23291 | 6.3.9600.23291 |
Is CVE-2026-54107 being exploited?
Public exploit code is available.
How to fix CVE-2026-54107
- Install the Microsoft updates that update affected builds to the fixed builds (for example 10.0.14393.9339, 10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548, 10.0.26100.8875, 10.0.26200.8875, 10.0.28000.2525, 6.2.9200.26226, and 6.3.9600.23291).
- If you cannot patch immediately, restrict untrusted local accounts and remove unnecessary local admin rights.
- Monitor endpoints for signs of local privilege escalation and review process creation and privilege change events.
Frequently asked questions
Is CVE-2026-54107 being actively exploited?
Public exploit code is available for CVE-2026-54107.
Which Windows versions are affected by CVE-2026-54107?
CVE-2026-54107 affects Windows 10 Version 1607 and multiple other Windows 10, Windows 11 and Windows Server branches; vendor advisories list the exact affected build ranges and fixed build numbers.
Is there a patch for CVE-2026-54107?
Yes; Microsoft released fixes that update affected builds to specific fixed builds such as 10.0.14393.9339, 10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548, 10.0.26100.8875, 10.0.26200.8875, 10.0.28000.2525, 6.2.9200.26226, and 6.3.9600.23291.
Does CVE-2026-54107 require authentication?
Yes; the vulnerability requires an authorized local account on the affected Windows host to exploit the Win32K race condition.
References
- nvd.nist.gov/vuln/detail/CVE-2026-54107
- cve.org/CVERecord?id=CVE-2026-54107
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54107
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026