July 2026 Patch TuesdayKB5099414Normal patch window

Microsoft · KB5099414

Linked CVE review

Deploy Microsoft Windows security update KB5099414

Linked CVEs
16
Confirmed exploited
0
PoC or lab evidence
0
Maximum CVSS
9.8
Evidence is kept separate

Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.

Reset
16 of 16 linked CVEs shown
Confirmed exploitedCVSS above 9.0
CVE and descriptionSeverityExploit realityForecast and accessRemediation
CVE-2026-42990 Critical technical severity
SQL Server ODBC driver Elevation of Privilege Vulnerability

Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network.

9.8 · CVSS 3.1 · CriticalSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.97% · 60.9th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interactionWithin 72 hoursCritical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
CVE-2026-49172 Critical technical severity
Windows FTP Service Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

9.8 · CVSS 3.1 · CriticalSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.97% · 60.9th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interactionWithin 72 hoursCritical technical impact with a remotely reachable, unauthenticated path; no CISA KEV confirmation is currently recorded.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
CVE-2026-40378 Scheduled assessment
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

7.5 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 1.17% · 66.6th percentileForecast date: 2026-10-07NETWORK · LOW complexity · NONE privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-50471 Scheduled assessment
Windows NTFS Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.47% · 38.4th percentileForecast date: 2026-10-07LOCAL · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
CVE-2026-58640 Scheduled assessment
Windows NTFS Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally.

7.3 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.36% · 27.6th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · REQUIRED user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-42982 Scheduled assessment
Windows Secure Kernel Mode Elevation of Privilege Vulnerability

Improper validation of consistency within input in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.33% · 24.6th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-58601 Scheduled assessment
Virtual Hard Disk (VHD) Miniport Driver Elevation of Privilege Vulernability

Heap-based buffer overflow in Virtual Hard Disk (VHD) Miniport Driver allows an authorized attacker to elevate privileges locally.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.33% · 24.5th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
CVE-2026-48571 Scheduled assessment
Windows App Package Installer Elevation of Privilege Vulnerability

Use after free in Windows App Installer allows an authorized attacker to elevate privileges locally.

7.0 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.26% · 16.7th percentileForecast date: 2026-10-07LOCAL · HIGH complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
CVE-2026-56173 Scheduled assessment
Windows WebView Elevation of Privilege Vulnerability

Use after free in Windows WebView allows an authorized attacker to elevate privileges locally.

7.0 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.26% · 16.7th percentileForecast date: 2026-10-07LOCAL · HIGH complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
CVE-2026-58629 Scheduled assessment
DirectX Graphics Kernel Elevation of Privilege Vulnerability

Use after free in Windows DirectX allows an authorized attacker to elevate privileges locally.

7.0 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.26% · 16.8th percentileForecast date: 2026-10-07LOCAL · HIGH complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-44800 Scheduled assessment
Windows Push Notifications Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

7.8 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.20% · 9.3th percentileForecast date: 2026-10-07LOCAL · HIGH complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Awaiting fix. No fixed version is explicitly recorded in the structured CVE data.
CVE-2026-48572 Scheduled assessment
Windows App Package Installer Elevation of Privilege Vulnerability

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.

7.0 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.20% · 9.3th percentileForecast date: 2026-10-07LOCAL · HIGH complexity · LOW privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
CVE-2026-34348 Scheduled assessment
Windows Event Logging Service Information Disclosure Vulnerability

Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.

6.5 · CVSS 3.1 · MediumSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 1.00% · 61.5th percentileForecast date: 2026-10-07NETWORK · LOW complexity · LOW privileges · NONE user interactionScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
CVE-2026-33842 Scheduled assessment
Windows File Explorer Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

5.5 · CVSS 3.1 · MediumSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.48% · 39.3th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interactionScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
CVE-2026-34328 Scheduled assessment
Windows Audio Service Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Audio Service allows an authorized attacker to disclose information locally.

5.5 · CVSS 3.1 · MediumSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.48% · 39.3th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interactionScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
CVE-2026-34346 Scheduled assessment
Windows Ancillary Function Driver for WinSock Information Disclosure Vulnerability

Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.

5.5 · CVSS 3.1 · MediumSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.27% · 17.6th percentileForecast date: 2026-10-07LOCAL · LOW complexity · LOW privileges · NONE user interactionScheduledMedium technical severity with no CISA KEV confirmation; remediate through the normal risk-based patch cycle unless local exposure raises the priority.Patch available. An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.