← console
voxell vciy

CVE-2026-26162: Windows OLE Elevation of Privilege Vulnerability

ROUTINE

Telemetry drift only. No threshold crossed and no authority ruling changed.

CVE record loaded 2026-09-20.

What to do now held facts and links

  1. Upgrade to the fixed version for your release line, or later: 10.0.14393.9060; 10.0.17763.8644; 10.0.19044.7184; 10.0.19045.7184; 10.0.22631.6936; 10.0.26100.8246; 10.0.26200.8246; 10.0.28000.1836; 6.2.9200.26026… CVE record
  2. Record your decision, dated and frozen with today's evidence: patch by a date · mitigated by a compensating control · deferred · accepted the risk · not affected
  3. Check your version against the ranges this record publishes.

What it is stated by the CNA

Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges locally.

weakness
CWE-843: Access of Resource Using Incompatible Type ('Type Confusion')
affected
Microsoft Windows 10 Version 1607; Microsoft Windows 10 Version 1809; Microsoft Windows 10 Version 21H2; Microsoft Windows 10 Version 22H2; Microsoft Windows 11 version 22H3; Microsoft Windows 11 Version 23H2; Microsoft Windows 11 Version 24H2; Microsoft Windows 11 Version 25H2; Microsoft Windows 11 version 26H1; Microsoft Windows Server 2012; Microsoft Windows Server 2012 (Server Core installation); Microsoft Windows Server 2012 R2; Microsoft Windows Server 2012 R2 (Server Core installation); Microsoft Windows Server 2016; Microsoft Windows Server 2016 (Server Core installation); Microsoft Windows Server 2019; Microsoft Windows Server 2019 (Server Core installation); Microsoft Windows Server 2022; Microsoft Windows Server 2022, 23H2 Edition (Server Core installation); Microsoft Windows Server 2025; Microsoft Windows Server 2025 (Server Core installation)
versions
Microsoft Windows 10 Version 1607 < 10.0.14393.9060; Microsoft Windows 10 Version 1809 < 10.0.17763.8644; Microsoft Windows 10 Version 21H2 < 10.0.19044.7184; Microsoft Windows 10 Version 22H2 < 10.0.19045.7184; Microsoft Windows 11 version 22H3 < 10.0.22631.6936; Microsoft Windows 11 Version 23H2 < 10.0.22631.6936; Microsoft Windows 11 Version 24H2 < 10.0.26100.8246; Microsoft Windows 11 Version 25H2 < 10.0.26200.8246; Microsoft Windows 11 version 26H1 < 10.0.28000.1836; Microsoft Windows Server 2012 < 6.2.9200.26026; Microsoft Windows Server 2012 (Server Core installation) < 6.2.9200.26026; Microsoft Windows Server 2012 R2 < 6.3.9600.23132; Microsoft Windows Server 2012 R2 (Server Core installation) < 6.3.9600.23132; Microsoft Windows Server 2016 < 10.0.14393.9060; Microsoft Windows Server 2016 (Server Core installation) < 10.0.14393.9060; Microsoft Windows Server 2019 < 10.0.17763.8644; Microsoft Windows Server 2019 (Server Core installation) < 10.0.17763.8644; Microsoft Windows Server 2022 < 10.0.20348.5020; Microsoft Windows Server 2022, 23H2 Edition (Server Core installation) < 10.0.25398.2274; Microsoft Windows Server 2025 < 10.0.26100.32690
published ranges
microsoft windows 10 1607 < 10.0.14393.9060; microsoft windows 10 1809 < 10.0.17763.8644; microsoft windows 10 21h2 < 10.0.19044.7184; microsoft windows 10 22h2 < 10.0.19045.7184; and 10 more on the CVE page
fixed in
10.0.14393.9060; 10.0.17763.8644; 10.0.19044.7184; 10.0.19045.7184; 10.0.22631.6936; 10.0.26100.8246; 10.0.26200.8246; 10.0.28000.1836; 6.2.9200.26026…
severity
7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
assigned by
microsoft
published
2026-04-14

check us msrc.microsoft.com

Exploit code held, dated

exploit code
None held in the PoC-in-GitHub feed. A public repository changes this brief.

What moved held, dated

dateEPSSevent
15 Apr 20260.00149
20 Apr 20260.00122
16 May 20260.00141
25 May 20260.00165
30 May 20260.00141
15 Jun 20260.00298scoring model v2026.06.15
28 Sep 20260.00333

7 observations held. A step marked with a scoring model moved because the measurement was replaced, not because the vulnerability changed.

Outside the record researched, cited

This section reads the record's references and adds cited findings from outside it. It needs an account. Everything above is held facts and is complete without it.

Sign in to add the researched section

What would change this brief held, dated

CISA KEV
Not listed in the catalogue we hold. A listing changes this brief.
exploit probability
0.00 on 2026-09-28 (FIRST's EPSS, a probability and not evidence of exploitation). Next band line: 10% (0.10). Crossing a line changes this brief.
fix
Held: 10.0.14393.9060; 10.0.17763.8644; 10.0.19044.7184; 10.0.19045.7184; 10.0.22631.6936; 10.0.26100.8246; 10.0.26200.8246; 10.0.28000.1836; 6.2.9200.26026… (CVE record, loaded 2026-09-20). A newer fix from the CNA or OSV changes this brief.

Watch this CVE What counts as a move

How to check this

Every value above is held with two dates: when it was true upstream (as_of) and when we recorded it (tx_from). Re-derive the exploit probability as it stood on any date:

SELECT value, source, source_version, as_of, tx_from
FROM volatile_valid_as_of('CVE-2026-26162', '2026-10-03T23:59:59.999999Z', now());

Identity above is quoted from the CVE Program record, corpus cvelistv5_20260920, recorded 30 Sep 2026.