CVE-2026-26181
vulnerability analysis and mitigation

Overview

CVE-2026-26181 is a use-after-free vulnerability in the Microsoft Brokering File System that allows an authorized local attacker to elevate privileges on affected Windows systems. It was disclosed and patched on April 14, 2026, as part of Microsoft's April 2026 Patch Tuesday security update cycle. Affected products include Windows 11 versions 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2022 (23H2 edition) and Windows Server 2025. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).

Technical details

The vulnerability is rooted in improper synchronization when the Microsoft Brokering File System handles shared resources, resulting in a race condition (CWE-362) that leads to a use-after-free condition (CWE-416). An attacker who wins the race can access memory after it has been freed, enabling arbitrary code execution in an elevated context. The attack vector is local, requires low privileges, no user interaction, and has low attack complexity, making it straightforward to exploit for any authenticated user on the system. No public proof-of-concept code has been identified at this time (Microsoft MSRC).

Impact

Successful exploitation allows an authenticated local attacker with low privileges to gain elevated — potentially SYSTEM-level — privileges on the affected host, resulting in high confidentiality, integrity, and availability impacts. This could enable an attacker to install malware, access sensitive data, disable security controls, or use the compromised system as a pivot point for lateral movement within a network. Affected systems span a broad range of modern Windows 11 and Windows Server deployments (Microsoft MSRC).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Microsoft MSRC). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.054%, indicating a low current probability of exploitation in the near term. No threat actor attribution has been reported.

Mitigation and workarounds

Microsoft released patches on April 14, 2026, addressing this vulnerability across all affected platforms. Administrators should apply the following patched builds: Windows 11 23H2 → 10.0.22631.6936, Windows 11 24H2 → 10.0.26100.8246 (also applies to Windows Server 2025), Windows 11 25H2 → 10.0.26200.8246, Windows 11 26H1 → 10.0.28000.1836, and Windows Server 2022 23H2 → 10.0.25398.2274. As interim measures, organizations should restrict local system access to trusted users only and monitor for suspicious privilege escalation activity (Microsoft MSRC).

Community reactions

The vulnerability was covered as part of broader April 2026 Patch Tuesday roundups by several security outlets. BleepingComputer noted it among 167 flaws fixed in the April 2026 update (BleepingComputer), and the Zero Day Initiative published a security update review for the same cycle (ZDI). Rapid7 and Sophos also included it in their Patch Tuesday analyses. No significant independent researcher commentary or social media discussion specific to this CVE has been identified.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management