Junglewise Threat Intelligence

CVE-2026-50694: Microsoft Windows SSTP use after free remote code execution

CVE-2026-50694 · Severity: high · CVSS 8.1 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Secure Socket Tunneling Protocol (SSTP), a service used to provide secure remote access via VPN connections. An attacker could exploit this flaw over the network to execute unauthorized code on a target system. If successful, this could allow a complete takeover of the affected server or workstation, potentially leading to data theft or service disruption.

Technical details

This vulnerability is classified as a use-after-free (CWE-416) within the Windows Secure Socket Tunneling Protocol (SSTP) stack. An unauthenticated attacker can exploit this over the network, though the attack complexity is rated as high, likely requiring specific timing or race conditions to successfully trigger the memory corruption. Successful exploitation allows for remote code execution (RCE) in the context of the affected service. Microsoft has released security updates to address this issue across multiple versions of Windows and Windows Server.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All editions

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory: Microsoft published the security update guide.

References

Related threats