CVE-2026-24294High· 7.8▾ MidnightPoC availableImproper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 42.9 · likelihood 0.9 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.8%
2.8% → 4.7%
1 GitHub repo
Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.
windows_10_1607 < 10.0.14393.8957windows_10_1809 < 10.0.17763.8511windows_10_21h2 < 10.0.19044.7058windows_10_22h2 < 10.0.19045.7058windows_11_23h2 < 10.0.22631.6783windows_11_24h2 < 10.0.26100.7979windows_11_25h2 < 10.0.26200.7979windows_11_26h1 < 10.0.28000.1719windows_server_2012windows_server_2012 = r2windows_server_2016 < 10.0.14393.8957windows_server_2019 < 10.0.17763.8511windows_server_2022 < 10.0.20348.4830windows_server_2022_23h2 < 10.0.25398.2207windows_server_2025 < 10.0.26100.32463Upgrade past the affected range:
windows_10_1607 10.0.14393.8957windows_10_1809 10.0.17763.8511windows_10_21h2 10.0.19044.7058windows_10_22h2 10.0.19045.7058windows_11_23h2 10.0.22631.6783windows_11_24h2 10.0.26100.7979windows_11_25h2 10.0.26200.7979windows_11_26h1 10.0.28000.1719windows_server_2016 10.0.14393.8957windows_server_2019 10.0.17763.8511windows_server_2022 10.0.20348.4830windows_server_2022_23h2 10.0.25398.2207windows_server_2025 10.0.26100.32463Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-85880High· 7.8Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVE-2026-33824Critical· 9.8Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
CVE-2026-54984High· 7.8Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.
CVE-2026-49179High· 8.8Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.
CVE-2026-32202Medium· 4.3Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
CVE-2018-8174High· 7.5A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1…