CVE-2026-61358
Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability
Description
Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowCVE-2026-61358 is a Windows local privilege escalation bug in ATBroker.exe; if someone already has a legitimate foothold on your device, patching is urgent for Windows 10/11 and Windows Server.
An elevation of privilege issue (CWE-59: improper link resolution before file access) in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized local attacker to elevate privileges on Windows 10/11 and Windows Server; fixed builds are listed by Microsoft for multiple releases.
What to do now
- Check whether your organization runs any of these affected systems: Windows 10, Windows 11, Windows Server 2019, Windows Server 2022, or Windows Server 2025.
- Identify your current Windows build number on each affected machine (Settings → System → About, or run
winver). - Compare each machine’s build against the fixed versions from Microsoft for CVE-2026-61358 and note any machine that is below the fixed build.
- Patch the affected machines by installing the Microsoft security update referenced for CVE-2026-61358 from the MSRC update guide.
- Verify the patch is installed (re-check the Windows build number) and ensure restart completes successfully.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-61358 and every CVE in our database. Create a free account — no credit card required.
Create Free Account