Information disclosure in Microsoft Windows and Windows Server - CVE-2026-50681
Published: July 17, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in Windows Cryptographic Services when handling cryptographic operations. A local user can access leaked internal memory pointers to disclose sensitive information.
The disclosed information is limited to internal memory pointers, which could help bypass security protections and facilitate further exploitation.
Affected software
Windows Server
How to mitigate CVE-2026-50681
Windows Server - addressed in versions 2012 R2 6.3.9600.23291, 2016 10.0.14393.9339, 2019 10.0.17763.9020, 2022 10.0.20348.5386, 2025 10.0.26100.33158