CVE-2026-26179Patch(microsoft / windows_11_23h2)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_11_23h2 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-415

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_11_23h2
  • windows_11_24h2
  • windows_11_25h2
  • windows_11_26h1

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-04-14); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2022_23h2windows_server_2025

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-14: 1Mentions · 2026-04-17: 1Mentions · 2026-06-06: 1Mentions · 2026-06-14: 1PoC Mentioned / Linked · 2026-06-06: 1Exploit Tool / Code · 2026-06-06: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-17: 1Technical Details · 2026-06-06: 104-1404-1706-0606-14
Signal classification4 categories
Patch
125.0%
Disclosure
125.0%
PoC
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-141
Patch1
2026-04-171
Disclosure1
2026-06-061
PoC1
2026-06-141
General1
Full discourse4 posts
  • dbugs@ptdbugs
    PoC

    🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-26179 PT ID: PT-2026-32756 Vendor: Microsoft Product: Windows 11 version 22H3 Description: Double free in Windows Kernel allows an authorized attacker to elevate privileges locally. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-32756 • https://github.com/nikosecurity/CVE-2026-26179 #dbugs_vuln

    Post summary

    A PoC and exploit code for CVE-2026-26179, a double‑free kernel vulnerability in Windows 11 22H3, has been discovered and shared on GitHub, but there is no indication of active exploitation or an available patch.

    00013589
    1.5K followersView on X
  • UniquePov@TangoZuloVictor
    General

    for the identification and analysis stages. It generated some nice posts for real recent CVEs (CVE-2026-33827, CVE-2026-26179, 2026-24289...) in the Windows kernel and TCPIP.sys. But then I tried to identify CVE-2026-26179 and CVE-2026-26169. Reading the reports carefully -->

    Post summary

    The text only lists CVE identifiers and mentions attempts to identify them, with no additional details about exploitation, patches, or technical characteristics.

    1000036
    20 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26179 Double free in Windows Kernel allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-26179

    Post summary

    A new Windows kernel double‑free vulnerability (CVE‑2026‑26179) that enables local privilege escalation has been publicly disclosed.

    00000139
    57.2K followersView on X
  • WindowsForum@windowsforum
    Patch

    🪟 CVE-2026-26179 smells like a juicy kernel EoP: low privilege → admin, aka “trust me bro” for attackers. Microsoft saying it’s real means patch now, not later. https://windowsforum.com/threads/cve-2026-26179-kernel-eop-why-microsoft-s-confidence-means-patch-now.412705/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #WindowsKernel #PrivilegeEscalation #Cve202626179 #MicrosoftSecurityGuidance

    Post summary

    The tweet emphasizes that Microsoft acknowledges CVE‑2026‑26179 as a real kernel privilege escalation flaw and urges users to patch immediately.

    0000032
    1.1K followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more