CVE-2026-32214
vulnerability analysis and mitigation

Overview

CVE-2026-32214 is an improper access control vulnerability in the Windows Universal Plug and Play service (upnp.dll) that allows a low-privileged local attacker to disclose sensitive information. Disclosed on April 14, 2026, as part of Microsoft's April 2026 Patch Tuesday, it affects a broad range of Windows versions including Windows 10 (1607 through 22H2), Windows 11 (23H2 through 26H1), Windows Server 2012 through 2025, and their Server Core variants. It carries a CVSS v3.1 base score of 5.5 (Medium) (Microsoft MSRC, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control) and resides in upnp.dll, the Windows UPnP service library. Due to insufficient access restrictions, an authorized but low-privileged local user can access resources or data that should be protected, resulting in unintended information disclosure. Exploitation requires local access and low privileges, with no user interaction needed, and the attack complexity is low. No public technical write-ups or proof-of-concept code have been identified at this time (Microsoft MSRC, GitHub Advisory).

Impact

Successful exploitation results in a high confidentiality impact — a low-privileged local attacker can read sensitive system information that should be inaccessible to them. There is no impact to integrity or availability. While the vulnerability is limited to local access and does not directly enable code execution or lateral movement, the disclosed information could potentially be leveraged to facilitate further attacks on the affected system (Microsoft MSRC).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.035–0.045%, placing it in the 14th percentile for exploitation likelihood within 30 days. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory, Feedly).

Mitigation and workarounds

Microsoft released patches on April 14, 2026, addressing this vulnerability across all affected Windows versions. Administrators should apply the relevant cumulative updates to reach the following minimum build versions:

  • Windows 11 23H2: 10.0.22631.6936
  • Windows 11 24H2: 10.0.26100.8246
  • Windows 11 25H2: 10.0.26200.8246
  • Windows 11 26H1: 10.0.28000.1836
  • Windows 10 21H2: 10.0.19044.7184
  • Windows 10 22H2: 10.0.19045.7184
  • Windows 10 1809: 10.0.17763.8644
  • Windows 10 1607: 10.0.14393.9060
  • Windows Server 2025: 10.0.26100.32690
  • Windows Server 2022: 10.0.20348.5020
  • Windows Server 2022 23H2: 10.0.25398.2274
  • Windows Server 2019: 10.0.17763.8644
  • Windows Server 2016: 10.0.14393.9060
  • Windows Server 2012 R2: 6.3.9600.23132
  • Windows Server 2012: 6.2.9200.26026

As a workaround, organizations should consider disabling the UPnP service if it is not required for business operations, and enforce the principle of least privilege to limit local user access (Microsoft MSRC).

Community reactions

CVE-2026-32214 was covered as part of broader April 2026 Patch Tuesday roundups. BleepingComputer reported on the full release of 167 fixes including this vulnerability, and Zero Day Initiative (ZDI) published its April 2026 security update review. Rapid7 also included it in their Patch Tuesday analysis. No significant standalone commentary or social media discussion specific to this CVE has been identified, consistent with its moderate severity and lack of active exploitation (BleepingComputer, ZDI, Rapid7).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management