CVE-2026-57094
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
Description
Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
In plain language
AI Act nowCVE-2026-57094 is a serious Windows Media Foundation flaw that could let an attacker run code over the network; if you’re running Windows 10/11 or Windows Server from the listed versions and haven’t installed the listed security updates, you should act now.
CVE-2026-57094 is a Windows Media Foundation heap-based buffer overflow that can be triggered remotely to achieve unauthorized remote code execution; it affects Windows 10/11 and Windows Server 2016/2019/2022/2025 and is fixed by the listed update build numbers.
What to do now
- Check your Windows version and exact build number (Settings → System → About; on servers use “winver”).
- Compare your build against the fixed builds below for your edition: Windows 10 fixed at 10.0.14393.9339 / 10.0.17763.9020 / 10.0.19044.7548 / 10.0.19045.7548; Windows 11 fixed at 10.0.26100.8875 / 10.0.26200.8875 / 10.0.28000.2269 / 10.0.28000.2525; Windows Server 2016 fixed at 10.0.14393.9339; Windows Server 2019 fixed at 10.0.17763.9020; Windows Server 2022 fixed at 10.0.20348.5386; Windows Server 2025 fixed at 10.0.26100.33158.
- Install the Microsoft security update for CVE-2026-57094 from the Microsoft Update Guide (msrc.microsoft.com) and then reboot.
- Verify after reboot that your build number matches a fixed value from the list in Step 2 and that Windows Update shows the update as installed.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft and Adobe Patch Tuesday, July 2026 Security Update Reviewen-us·Qualys Security Blog· Patch Windows patch-tuesday
- Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Active Directory Federation Services (AD FS) rce
- Microsoft Patch Tuesday July 2026 - The AI Acopolypse is Hereen·SANS Internet Storm Center· Exploited Windows privilege-escalation
- Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-daysen-us·BleepingComputer· Exploited .NET zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-57094 and every CVE in our database. Create a free account — no credit card required.
Create Free Account