Junglewise Threat Intelligence

CVE-2026-50360: Microsoft Windows SMB Server privilege escalation

CVE-2026-50360 · Severity: high · CVSS 8.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2025, Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows SMB Server, which is the component responsible for file and printer sharing across a network. An attacker who already has basic user access to the network could exploit this flaw to gain higher-level administrative privileges. This could allow an unauthorized individual to access sensitive data, modify system configurations, or disrupt business operations.

Technical details

A privilege escalation vulnerability exists in the Windows SMB Server due to an incorrect implementation of an authentication algorithm (CWE-303). The vulnerability is reachable over the network (AV:N) but requires the attacker to possess low-privileged credentials (PR:L). By exploiting this flaw, an authenticated attacker can bypass intended security restrictions to gain elevated privileges on the target system. Microsoft has released security updates for affected versions of Windows 10, Windows 11, and Windows Server to address this issue.

Affected products

  • Microsoft Windows 10 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2022 All versions
  • Microsoft Windows Server 2025 All versions

Timeline

  • 2026-07-14: disclosed: Initial publication by Microsoft and NVD.
  • 2026-07-14: patched: Security updates released by Microsoft.

References

Related threats