DIRAS TAKE
Urgent: public exploit code exists, so prioritize installing the vendor fixes for impacted builds or restrict local exposure immediately.
What is CVE-2026-54984?
A local attacker can execute arbitrary code on affected Windows installations via a heap-based buffer overflow in the Windows Imaging Component (CVE-2026-54984). Multiple Windows 10, Windows 11 and Windows Server 2012 branches are affected; affected builds include Windows 10 Version 1607 (10.0.14393.0 through before 10.0.14393.9418) and other listed build ranges. The vulnerability requires local access and user interaction to trigger, and fixes are available in the vendor-supplied builds. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).
Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1607 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1607 10.x | 10.0.14393.0 – before 10.0.14393.9418 | 10.0.14393.9418 |
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9121 | 10.0.17763.9121 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7663 | 10.0.19044.7663 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7663 | 10.0.19045.7663 |
| Windows 11 version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7517 | 10.0.22631.7517 |
| Windows 11 Version 23H2 10.x | 10.0.22631.0 – before 10.0.22631.7517 | 10.0.22631.7517 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.9168 | 10.0.26100.9168 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.9168 | 10.0.26200.9168 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2704 | 10.0.28000.2704 |
| Windows Server 2012 6.x | 6.2.9200.0 – before 6.2.9200.26280 | 6.2.9200.26280 |
Is CVE-2026-54984 being exploited?
Public exploit code is available.
How to fix CVE-2026-54984
- Install the Microsoft updates that include the fixed builds (for example 10.0.14393.9418 for Windows 10 Version 1607 and the corresponding fixed builds for other branches).
- If you cannot yet patch, restrict local access to affected systems and limit who can open untrusted images or files.
- Monitor endpoints for suspicious activity and review logs for signs of code execution or anomalous process launches.
- Follow Microsoft guidance for deploying the updates and validating successful installation.
Frequently asked questions
Is CVE-2026-54984 being actively exploited?
Public exploit code for CVE-2026-54984 is available.
Which Windows 10 Version 1607 versions are affected by CVE-2026-54984?
Windows 10 Version 1607 builds from 10.0.14393.0 up to but not including 10.0.14393.9418 are affected; the issue is fixed in build 10.0.14393.9418.
Is there a patch for CVE-2026-54984?
Yes. Microsoft published updates that include fixed builds such as 10.0.14393.9418 for Windows 10 Version 1607 and corresponding fixed builds for other affected branches.
Does CVE-2026-54984 require authentication?
No prior account privileges are required, but the flaw requires local access and user interaction to trigger on affected Windows systems.
References
- nvd.nist.gov/vuln/detail/CVE-2026-54984
- cve.org/CVERecord?id=CVE-2026-54984
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-54984
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026