Junglewise Threat Intelligence

CVE-2026-56186: Microsoft Windows Schannel out-of-bounds read

CVE-2026-56186 · Severity: high · CVSS 8.1 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Schannel component, which handles secure network communications (SSL/TLS) for the operating system. An authorized user on the network could exploit this flaw to access sensitive information or cause a system crash. This could lead to data exposure or service disruptions across affected Windows and Windows Server environments.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the Microsoft Schannel security package. The flaw is triggered when the component improperly handles specially crafted network packets. An attacker with low-level authentication (PR:L) can exploit this over the network without user interaction to read memory contents or potentially cause a denial-of-service condition. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server 2012. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 Standard and Server Core

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory: Microsoft released security update guide.

References

Related threats