CVE-2026-54986
Windows Win32k Elevation of Privilege Vulnerability
Description
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowCVE-2026-54986 is a Windows local privilege-upgrade flaw that can let someone with already-present access gain higher system control; small businesses should act because it affects common Windows versions and is fixed in specific updates.
CVE-2026-54986 is a local elevation of privilege in the Windows Win32k subsystem (CWE-122 heap-based buffer overflow), where an authorized attacker can trigger the bug to gain higher privileges; patching is available for all listed Windows releases and the issue is rated RED.
What to do now
- Identify which of these you run: windows 10, windows 11, windows server 2016, windows server 2019, windows server 2022, windows server 2025 (and your current OS build number).
- For each affected OS, upgrade to the fixed build that matches your version: windows 10 → 10.0.14393.9339 or 10.0.17763.9020 or 10.0.19044.7548 or 10.0.19045.7548.
- For windows 11, upgrade to: 10.0.26100.8875 or 10.0.26200.8875 or 10.0.28000.2525.
- For Windows Server, upgrade to the fixed build for your release: server 2016 → 10.0.14393.9339; server 2019 → 10.0.17763.9020; server 2022 → 10.0.20348.5386; server 2025 → 10.0.26100.33158.
- After updating, verify the OS build in your system info matches the fixed build and confirm your endpoint management reports the updated state.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft and Adobe Patch Tuesday, July 2026 Security Update Reviewen-us·Qualys Security Blog· Patch Windows patch-tuesday
- Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Active Directory Federation Services (AD FS) rce
- Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Hereen·SANS Internet Storm Center· Exploited Windows privilege-escalation
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-daysen-us·BleepingComputer· Exploited .NET zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-54986 and every CVE in our database. Create a free account — no credit card required.
Create Free Account