Windows hard link in Microsoft Windows and Windows Server - CVE-2026-70019
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to read files from the file system.
The vulnerability exists due to a Windows hard link in Windows Compressed Folder when processing a compressed folder containing a Windows hard link. A remote attacker can use a Windows hard link in a compressed folder to read files from the file system.
User interaction is required.
Affected software
Windows Server
How to mitigate CVE-2026-70019
Windows Server - update to 2025 10.0.26100.33438