DIRAS TAKE
Urgent: public exploit code exists, so prioritize updates; the strongest immediate mitigation is to install Microsoft’s fixed builds or restrict local account access until patched.
What is CVE-2026-58635?
Local, low-privileged users can exploit a command-injection flaw in the Windows Narrator Braille component to obtain elevated privileges on affected Windows builds. CVE-2026-58635 affects multiple Windows 10, Windows 11 and Windows Server branches (see affected builds below); Microsoft notes affected ranges starting at 10.0.17763.0 and other branch-specific ranges and provides fixed builds. An attacker requires local access with a low-privilege account (no user interaction) to trigger the issue. The weakness is classified as CWE-77 (Command Injection).
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 10 Version 1809 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 10 Version 1809 10.x | 10.0.17763.0 – before 10.0.17763.9020 | 10.0.17763.9020 |
| Windows 10 Version 21H2 10.x | 10.0.19044.0 – before 10.0.19044.7548 | 10.0.19044.7548 |
| Windows 10 Version 22H2 10.x | 10.0.19045.0 – before 10.0.19045.7548 | 10.0.19045.7548 |
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.8875 | 10.0.26100.8875 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.8875 | 10.0.26200.8875 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2525 | 10.0.28000.2525 |
| Windows Server 2019 10.x | 10.0.17763.0 – before 10.0.17763.9020 | 10.0.17763.9020 |
| Windows Server 2019 (Server Core installation) 10.x | 10.0.17763.0 – before 10.0.17763.9020 | 10.0.17763.9020 |
| Windows Server 2022 10.x | 10.0.20348.0 – before 10.0.20348.5386 | 10.0.20348.5386 |
| Windows Server 2025 10.x | 10.0.26100.0 – before 10.0.26100.33158 | 10.0.26100.33158 |
Is CVE-2026-58635 being exploited?
Public exploit code is available.
How to fix CVE-2026-58635
- Install Microsoft fixes for affected branches (examples include 10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548, 10.0.26100.8875, 10.0.26200.8875, 10.0.28000.2525, 10.0.20348.5386, 10.0.26100.33158).
- If you cannot patch immediately, restrict or remove untrusted local accounts and limit administrative access on endpoints with Narrator Braille.
- Monitor logs and endpoint telemetry for suspicious local process creation and attempts to invoke Narrator Braille components.
- Follow Microsoft guidance for any additional mitigations and apply updates through your normal patch management process.
Frequently asked questions
Is CVE-2026-58635 being actively exploited?
Public exploit code is available for CVE-2026-58635.
Which Windows versions are affected by CVE-2026-58635?
Windows 10, Windows 11 and several Windows Server branches are listed as affected; Microsoft provides branch-specific affected ranges (for example starting at 10.0.17763.0 for some 10.x branches) — consult the vendor’s affected list for exact build ranges.
Is there a patch for CVE-2026-58635?
Yes. Microsoft published fixed builds for each affected branch; examples include 10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548 and others listed in the vendor’s advisory.
Does CVE-2026-58635 require authentication?
Yes. The flaw requires a local, authorized (low-privilege) account on the affected Windows builds to exploit; no additional user interaction is required.
References
- nvd.nist.gov/vuln/detail/CVE-2026-58635
- cve.org/CVERecord?id=CVE-2026-58635
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58635
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026