
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26172 is a local privilege escalation vulnerability in the Windows Push Notifications service caused by a race condition (CWE-362) combined with a use-after-free condition (CWE-416). It affects a broad range of Microsoft Windows versions including Windows 10 21H2/22H2, Windows 11 23H2/24H2/25H2/26H1, Windows Server 2022, Windows Server 2022 23H2, and Windows Server 2025. The vulnerability was publicly disclosed and patched on April 14, 2026, as part of Microsoft's monthly Patch Tuesday security update cycle. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The root cause is improper synchronization of concurrent execution using a shared resource within the Windows Push Notifications service (CWE-362), which can lead to a use-after-free condition (CWE-416). An attacker with low-privileged local access can exploit the race condition by timing concurrent operations to corrupt memory state, ultimately gaining elevated execution privileges. The attack vector is local, requires low privileges, no user interaction, and has high attack complexity — consistent with a TOCTOU (Time-of-Check to Time-of-Use) exploitation pattern (CAPEC-29). No public proof-of-concept code has been identified at this time (Microsoft MSRC).
Successful exploitation allows a low-privileged local attacker to escalate to SYSTEM-level privileges, resulting in high confidentiality, integrity, and availability impact with a changed scope. This means an attacker could access sensitive data, modify system configurations or files, and potentially cause denial of service on the affected host. The changed scope indicates the vulnerability's impact extends beyond the initially compromised process, enabling broader system compromise and potential lateral movement within an environment (Microsoft MSRC).
As of the time of disclosure, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation of CVE-2026-26172. The EPSS score is approximately 0.049% (0.000490), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. High attack complexity is a mitigating factor, as successful exploitation requires precise timing to win the race condition (Microsoft MSRC).
svchost.exe hosting the Windows Push Notifications service.%SystemRoot%\System32) by non-administrative accounts; new scheduled tasks or services created post-exploitation.Microsoft released security updates on April 14, 2026 (Patch Tuesday) addressing this vulnerability across all affected Windows versions. Administrators should apply the following patched builds: Windows 10 21H2/22H2 → 10.0.19044.7184 / 10.0.19045.7184; Windows 11 23H2 → 10.0.22631.6936; Windows 11 24H2 → 10.0.26100.8246 (or 10.0.26100.32690 for Server 2025); Windows 11 25H2 → 10.0.26200.8246; Windows 11 26H1 → 10.0.28000.1836; Windows Server 2022 → 10.0.20348.5020; Windows Server 2022 23H2 → 10.0.25398.2274. As a compensating control where patching is not immediately possible, restrict local user access and enforce the principle of least privilege to reduce the attack surface (Microsoft MSRC).
The vulnerability was covered as part of broader April 2026 Patch Tuesday roundups by security vendors including Rapid7, Sophos, and Lansweeper, which noted it among the privilege escalation vulnerabilities addressed that month. No specific high-profile researcher commentary or significant social media discussion has been identified for this individual CVE, consistent with its moderate severity and lack of active exploitation (Rapid7 Blog, Sophos Blog, Lansweeper Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."