CVE-2026-23674Disclosure(microsoft / windows_10_1607)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-41

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-11); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 14 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-11: 1Mentions · 2026-03-12: 1Mentions · 2026-03-16: 1Technical Details · 2026-03-16: 103-1103-1203-16
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-111
Disclosure1
2026-03-121
General1
2026-03-161
Disclosure1
Full discourse3 posts
  • Brian in Pittsburgh@arekfurt
    General

    Internet Explorer will outlive us all. https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-23674 https://t.co/dxko1EKQXC

    Post summary

    The tweet references CVE-2026-23674 via a Microsoft update guide link but provides no additional information about the vulnerability.

    10051913
    6.9K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-23674 Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. https://www.cve.org/CVERecord?id=CVE-2026-23674

    Post summary

    The text announces CVE‑2026‑23674, describing a Windows MapUrlToZone path resolution flaw that permits a security bypass over a network, without providing any PoC, exploit, or patch information.

    00000185
    56.7K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-23674 - Microsoft - Windows 10 Version 1607 - https://www.redpacketsecurity.com/cve-alert-cve-2026-23674-microsoft-windows-10-version-1607/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-23674 #microsoft #windows-10-version-1607

    Post summary

    The post announces CVE‑2026‑23674 for Microsoft Windows 10 Version 1607, linking to a CVE alert page, but provides no PoC, exploitation, patch, or technical details.

    0000094
    3.5K followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025--x64

Explore more