CVE-2026-26172
vulnerability analysis and mitigation

Overview

CVE-2026-26172 is a local privilege escalation vulnerability in the Windows Push Notifications service caused by a race condition (CWE-362) combined with a use-after-free condition (CWE-416). It affects a broad range of Microsoft Windows versions including Windows 10 21H2/22H2, Windows 11 23H2/24H2/25H2/26H1, Windows Server 2022, Windows Server 2022 23H2, and Windows Server 2025. The vulnerability was publicly disclosed and patched on April 14, 2026, as part of Microsoft's monthly Patch Tuesday security update cycle. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).

Technical details

The root cause is improper synchronization of concurrent execution using a shared resource within the Windows Push Notifications service (CWE-362), which can lead to a use-after-free condition (CWE-416). An attacker with low-privileged local access can exploit the race condition by timing concurrent operations to corrupt memory state, ultimately gaining elevated execution privileges. The attack vector is local, requires low privileges, no user interaction, and has high attack complexity — consistent with a TOCTOU (Time-of-Check to Time-of-Use) exploitation pattern (CAPEC-29). No public proof-of-concept code has been identified at this time (Microsoft MSRC).

Impact

Successful exploitation allows a low-privileged local attacker to escalate to SYSTEM-level privileges, resulting in high confidentiality, integrity, and availability impact with a changed scope. This means an attacker could access sensitive data, modify system configurations or files, and potentially cause denial of service on the affected host. The changed scope indicates the vulnerability's impact extends beyond the initially compromised process, enabling broader system compromise and potential lateral movement within an environment (Microsoft MSRC).

Exploitability

As of the time of disclosure, there is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation of CVE-2026-26172. The EPSS score is approximately 0.049% (0.000490), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. High attack complexity is a mitigating factor, as successful exploitation requires precise timing to win the race condition (Microsoft MSRC).

Exploitation steps

  1. Reconnaissance: Identify a target Windows system running an unpatched version of Windows 10 21H2/22H2, Windows 11 23H2–26H1, or Windows Server 2022/2025 with local access available.
  2. Gain initial access: Obtain a low-privileged local user account on the target system (e.g., via phishing, credential theft, or existing foothold).
  3. Target the Push Notifications service: Identify the Windows Push Notifications service (WpnService) and its shared memory/resource handling routines as the exploitation target.
  4. Trigger race condition: Craft and execute concurrent threads or processes that simultaneously access the shared resource within the Push Notifications service, attempting to win the TOCTOU race window to cause a use-after-free memory condition.
  5. Exploit use-after-free: Leverage the freed memory region to inject or redirect execution flow to attacker-controlled code or data, achieving privilege escalation.
  6. Achieve SYSTEM privileges: Upon successful exploitation, execute arbitrary code in the context of SYSTEM, enabling full control of the compromised host (Microsoft MSRC).

Indicators of compromise

  • Process: Unexpected processes spawned with SYSTEM-level privileges from a low-privileged user context; unusual child processes of svchost.exe hosting the Windows Push Notifications service.
  • Logs: Windows Security Event Log entries showing privilege escalation (Event ID 4672 – Special privileges assigned to new logon) for accounts that should not hold such rights; Event ID 4688 showing process creation with elevated tokens from unexpected parent processes.
  • File System: Unexpected files written to protected system directories (e.g., %SystemRoot%\System32) by non-administrative accounts; new scheduled tasks or services created post-exploitation.
  • Network: Outbound connections from SYSTEM-level processes to unusual external IP addresses, potentially indicating post-exploitation activity such as C2 communication or data exfiltration.

Mitigation and workarounds

Microsoft released security updates on April 14, 2026 (Patch Tuesday) addressing this vulnerability across all affected Windows versions. Administrators should apply the following patched builds: Windows 10 21H2/22H2 → 10.0.19044.7184 / 10.0.19045.7184; Windows 11 23H2 → 10.0.22631.6936; Windows 11 24H2 → 10.0.26100.8246 (or 10.0.26100.32690 for Server 2025); Windows 11 25H2 → 10.0.26200.8246; Windows 11 26H1 → 10.0.28000.1836; Windows Server 2022 → 10.0.20348.5020; Windows Server 2022 23H2 → 10.0.25398.2274. As a compensating control where patching is not immediately possible, restrict local user access and enforce the principle of least privilege to reduce the attack surface (Microsoft MSRC).

Community reactions

The vulnerability was covered as part of broader April 2026 Patch Tuesday roundups by security vendors including Rapid7, Sophos, and Lansweeper, which noted it among the privilege escalation vulnerabilities addressed that month. No specific high-profile researcher commentary or significant social media discussion has been identified for this individual CVE, consistent with its moderate severity and lack of active exploitation (Rapid7 Blog, Sophos Blog, Lansweeper Blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management