Junglewise Threat Intelligence

CVE-2026-50439: Microsoft Message Queuing use after free in Queue Manager

CVE-2026-50439 · Severity: high · CVSS 8.1 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A vulnerability exists in the Microsoft Message Queuing (MSMQ) service, which is used by Windows systems to handle communications between different applications. An attacker could exploit this flaw over a network to gain control of the affected system or disrupt its operations. This could lead to unauthorized access to sensitive data or a complete service outage for critical business applications that rely on message queuing.

Technical details

This vulnerability is classified as a Use-After-Free (CWE-416) within the Microsoft Message Queuing (MSMQ) Queue Manager component. The flaw is reachable over the network and does not require user interaction or prior authentication, though the CVSS vector indicates high attack complexity, suggesting specific timing or environmental conditions are necessary for successful exploitation. If successfully exploited, an attacker can achieve remote code execution (RCE) in the context of the MSMQ service. Microsoft has released security updates to address this issue across various versions of Windows and Windows Server.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All versions

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats