CVE-2026-26169General(microsoft / windows_10_1607)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-126

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-14); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2016windows_server_2019

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-04-14: 2Mentions · 2026-04-15: 2Mentions · 2026-06-14: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-15: 104-1404-1506-14
Signal classification3 categories
General
360.0%
Patch
120.0%
Disclosure
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-142
General1Patch1
2026-04-152
Disclosure1General1
2026-06-141
General1
Full discourse5 posts
  • Masahiro Kawada@kawakatz
    General

    デニスさんにWindows自体のゼロデイ調査について教えていただいた時の思い出CVE公開されてた🥰 共同作業というには程遠かったけど😶‍🌫️ https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26169 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32162

    Post summary

    The post remarks on two CVEs with links to Microsoft’s updates, but offers no additional information on exploitation, patches, or technical specifics.

    0001141.5K
    882 followersView on X
  • UniquePov@TangoZuloVictor
    General

    for the identification and analysis stages. It generated some nice posts for real recent CVEs (CVE-2026-33827, CVE-2026-26179, 2026-24289...) in the Windows kernel and TCPIP.sys. But then I tried to identify CVE-2026-26179 and CVE-2026-26169. Reading the reports carefully -->

    Post summary

    The snippet merely lists CVE identifiers and notes that posts were generated for them, without providing any further technical, exploitative, or remedial details.

    1000036
    20 followersView on X
  • kawn@kawn2020
    General

    #windowsupdate #microsoft つづき ・CVE-2026-26169 6.1 Windows カーネル メモリ ・CVE-2026-27906 4.4 Windows Hello ・CVE-2026-27908 7  Windows TDI 翻訳ドライバー(tdx.sys) ・CVE-2026-27909 7.8 Microsoft Windows 検索コンポーネント ・CVE-2026-27913 7.7 Windows BitLocker …

    Post summary

    The tweet enumerates several Windows CVEs with short component references but offers no additional detail on exploitation, patches, or technical depth.

    10000189
    85 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26169 Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally. https://www.cve.org/CVERecord?id=CVE-2026-26169

    Post summary

    The message announces the existence of CVE‑2026‑26169, describing a buffer over‑read in Windows kernel memory that permits local information disclosure, without providing exploitation or mitigation details.

    00000151
    57.2K followersView on X
  • WindowsForum@windowsforum
    Patch

    🪟 CVE-2026-26169 is basically Microsoft saying “trust us, but we’re also grading our certainty.” The confidence level matters more than the drama—patch accordingly, don’t vibes-only it. https://windowsforum.com/threads/cve-2026-26169-how-windows-kernel-info-disclosure-confidence-signals-risk.412963/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #WindowsKernel #InformationDisclosure #SecurityUpdateGuide

    Post summary

    The comment highlights the importance of applying Microsoft’s patch for CVE‑2026‑26169, stressing that the confidence in the advisory varies and that users should not ignore official guidance.

    0000029
    1.1K followersView on X
CPE platform detail23 entries

23 of 23 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more