CVE-2026-2636PoC

MEDIUMCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

This vulnerability is caused by a CWE‑159: "Improper Handling of Invalid Use of Special Elements" weakness, which leads to an unrecoverable inconsistency in the CLFS.sys driver. This condition forces a call to the KeBugCheckEx function, allowing an unprivileged user to trigger a system crash. Microsoft silently fixed this vulnerability in the September 2025 cumulative update for Windows 11 2024 LTSC and Windows Server 2025. Windows 25H2 (released in September) was released with the patch. Windows 1123h2 and earlier versions remain vulnerable.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-159

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 19 mentions across 6 observed days
  • Momentum state: declining

What's happening

  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 13 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 15 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • Peaked 4d ago at 13 mentions (2026-02-26); latest day: 1
  • 19 total mentions across 6 days

Deep dive

Activity timeline19 mentions / 6d
0371013Mentions · 2026-02-25: 1Mentions · 2026-02-26: 13Mentions · 2026-02-27: 2Mentions · 2026-03-05: 1Mentions · 2026-03-13: 1Mentions · 2026-03-14: 1PoC Mentioned / Linked · 2026-02-25: 1PoC Mentioned / Linked · 2026-02-26: 9PoC Mentioned / Linked · 2026-02-27: 1PoC Mentioned / Linked · 2026-03-05: 1PoC Mentioned / Linked · 2026-03-13: 1Exploit Tool / Code · 2026-02-26: 4Exploit Tool / Code · 2026-03-05: 1Patch / Workaround · 2026-02-26: 4Patch / Workaround · 2026-02-27: 1Technical Details · 2026-02-25: 1Technical Details · 2026-02-26: 10Technical Details · 2026-02-27: 2Technical Details · 2026-03-05: 1Technical Details · 2026-03-13: 102-2502-2602-2703-0503-1303-14
Signal classification3 categories
PoC
1263.2%
Disclosure
421.1%
General
315.8%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-02-251
PoC1
2026-02-2613
Disclosure2General2PoC9
2026-02-272
Disclosure2
2026-03-051
PoC1
2026-03-131
PoC1
2026-03-141
General1
Full discourse19 posts
  • Cyber Security News@The_Cyber_News
    PoC

    🛡️ PoC Released for Windows 11 Vulnerability Causing Unrecoverable BSOD Crashes Source: https://cybersecuritynews.com/windows-vulnerability-bsod-crashes/ A proof-of-concept (PoC) exploit has been publicly released for CVE-2026-2636, a newly documented vulnerability in Windows’ Common Log File System (CLFS) driver that allows any low-privileged, unprivileged user to instantly crash a target system into an unrecoverable Blue Screen of Death (BSoD). The vulnerability stems from improper flag validation within the CLFS!CClfsRequest::ReadLogPagingIo function inside CLFS.sys. #cybersecuritynews

    Post summary

    A PoC exploit for CVE-2026-2636 has been released, demonstrating a low‑privilege BSoD vulnerability in Windows CLFS, but no active exploitation or patch information is provided.

    7422123377.7K
    49.3K followersView on X
  • Core Impact@_CoreImpact
    PoC

    In his latest blog, @ricnar456 provides a PoC related to CVE-2026-2636, a blue screen of death (BSoD) on Windows CLFS driver https://www.coresecurity.com/blog/cve-2026-2636-blf-log-file-unrecoverable-state-bsod https://t.co/sKBbYUe63g

    Post summary

    The blog post shares a PoC for CVE-2026-2636, a BSoD issue in the Windows CLFS driver, but does not provide exploit code, patch information, or evidence of active exploitation.

    119064364.1K
    65.2K followersView on X
  • Fortra@fortraofficial
    PoC

    A PoC exploit for CVE-2026-2636 shows how a low-privileged user can crash Windows systems into an unrecoverable BSOD. The CLFS driver flaw was discovered by Fortra researcher Ricardo Narvaja during vulnerability research. More details: https://hubs.la/Q046Hhv30

    Post summary

    The post announces a Proof of Concept exploit for CVE-2026-2636 that allows low-privileged users to crash Windows systems via the CLFS driver, with a link for more information.

    07030172.3K
    2.6K followersView on X
  • Juan Carlos Ortiz 🛡️ Ciberseguridad para Empresas@CycuraMX
    PoC

    🛡️ CVE-2026-2636: un usuario sin permisos puede tumbar Windows con “pantalla azul” irreversible Ya circula un PoC para una falla de Windows. Un PoC es una “prueba” pública que demuestra cómo se explota, y facilita que cualquiera la replique. El impacto principal es detener la operación por completo. Esto es especialmente riesgoso en equipos compartidos. Recepción, almacén, puntos de venta, kioscos, aulas y PCs con varios usuarios. Un solo usuario “básico” podría tirar la máquina en segundos. ⚠️ ¿Qué pasó? La falla es CVE-2026-2636. Afecta al componente CLFS de Windows, el cual es un sistema usado para manejar ciertos registros internos. Facilita un DoS. Es decir, ataques que dejan un sistema fuera de servicio, sin robar datos necesariamente. El resultado es un BSOD, la “pantalla azul” que detiene Windows por un error crítico. Lo grave es que puede quedar “irrecuperable” hasta reinicio/recuperación. Fortra reporta que Microsoft lo corrigió en actualizaciones de septiembre 2025 para Windows 11 2024 LTSC y Windows Server 2025 Windows 11 23H2 y anteriores seguirían expuestos. 💡 ¿Qué deben hacer? Pidan a TI verificar versión de Windows y aplicar parches de septiembre 2025 o posteriores. Limiten quién puede iniciar sesión localmente en equipos críticos. Eviten “PCs compartidas” con cuentas genéricas. Usen cuentas por persona. Prioricen parches en kioscos, cajas, recepción y salas de capacitación. Son los más expuestos. Monitoreen reinicios inesperados y eventos de “pantalla azul”. Ayuda a detectar abuso temprano. 📩 En CycuraMX ayudamos a reducir caídas por vulnerabilidades y a ordenar parches por prioridad real. Si quieres blindarte, escríbenos a cycuramx@protonmail.com

    Post summary

    A PoC for CVE‑2026‑2636 demonstrates a DoS via the CLFS component that can cause an irreversible BSOD; Microsoft released a patch in September 2025, and users are advised to apply it and restrict local logins on critical machines.

    1902271.2K
    7.5K followersView on X
  • blueblue@piedpiper1616
    Disclosure

    CVE-2026-2636: Using ReadFile with Handle of Opened .blf Log File Produces an Unrecoverable State in CLFS.sys Causing a BSoD - https://www.coresecurity.com/blog/cve-2026-2636-blf-log-file-unrecoverable-state-bsod

    Post summary

    A new CVE (CVE-2026-2636) is disclosed, explaining how ReadFile on an opened .blf log file can cause a kernel‑mode crash (BSoD) in CLFS.sys.

    06017101.8K
    5.5K followersView on X
  • ThreatSynop@ThreatSynop
    PoC

    🚨 PoC drops for Windows CLFS bug (CVE-2026-2636) that lets any low-priv user trigger unrecoverable BSOD A public PoC for CVE-2026-2636 abuses improper flag validation in Windows’ CLFS.sys (via a simple CreateLogFile → ReadFile sequence) to force KeBugCheckEx and crash systems without admin rights, making it an easy DoS weapon in shared/enterprise environments. Microsoft quietly fixed it in September 2025 updates for newer builds, but Windows 11 23H2 and earlier remain exposed and should be patched or access-restricted. 🎯 Target: Global/Windows #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/windows-vulnerability-bsod-crashes/

    Post summary

    A public PoC for CVE‑2026‑2636 shows a low‑privilege DoS via CLFS.sys, with Microsoft patching the issue in September 2025 but older Windows 11 builds remain vulnerable.

    02021154
    221 followersView on X
  • Israel@f1tym1
    PoC

    PoC Released for Windows Vulnerability That Allows Attackers to Cause Unrecoverable BSOD Crashes https://ift.tt/qFp24ol A proof-of-concept (PoC) exploit has been publicly released for CVE-2026-2636, a newly documented vulnerability in Windows’ Common Log File System (CLFS) dr…

    Post summary

    A PoC exploit for CVE-2026-2636 has been publicly released, demonstrating a Windows CLFS vulnerability that can cause unrecoverable BSOD crashes.

    0000279
    931 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-25253 2 - CVE-2024-23222 3 - CVE-2026-3909 4 - CVE-2026-21643 5 - CVE-2026-2636 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five CVEs as trending but offers no additional details on the vulnerabilities, exploits, or mitigation efforts.

    00010160
    1.7K followersView on X
  • iototsecnews@iototsecnews
    PoC

    Windows の脆弱性 CVE-2026-2636 に PoC:CLFS ドライバーの問題によるBSoD クラッシュを実証 https://iototsecnews.jp/2026/02/26/poc-released-for-windows-vulnerability-that-allows-attackers-to-cause-unrecoverable-bsod-crashes/ Windows のログ管理を担う Common Log File System (CLFS) ドライバーに、深刻な脆弱性 CVE-2026-2636 が存在します。低権限のユーザーであっても、この脆弱性の悪用により、システムを即座にクラッシュさせ、ブルー画面 (BSoD) を引き起こすことが可能だとされます。さらに、PoC エクスプロイト・コードが公開され、Windows バージョンの確認などが、喫緊のテーマとなっています。 この脆弱性の恐ろしさは、特別なハッキング技術や複雑なコードを必要とせず、わずか2つの標準的な Windows API を呼び出すだけで、攻撃が成立してしまう点にあります。具体的には、ログファイルを開くための CreateLogFile を実行した後に、本来の設計では想定されていない ReadFile を、そのハンドルに対して呼び出すだけで、カーネル内部で修復不可能な矛盾が生じ、Windows が強制終了されます。 #CVE20262636 #Microsoft #PoC #Vulnerability #Windows

    Post summary

    A PoC exploit for CVE‑2026‑2636 is publicly available, demonstrating that a low‑privilege user can trigger an unrecoverable BSOD by abusing CLFS driver API calls.

    01000167
    483 followersView on X
  • Danilo AV@aragonverdooren
    General

    @CycuraMX @grok Explícame como ejecutan la vulnerabilidad CVE-2026-2636

    Post summary

    The user is requesting instructions on how to exploit CVE-2026-2636, but the text provides no additional details or evidence.

    1000050
    78 followersView on X
  • WindowsForum@windowsforum
    PoC

    🪳 PoC makes CLFS meltdown trigger a near-irrecoverable BSoD with standard user rights—yikes. Time to patch and reboot responsibly! #WindowsForum #CVE2026 #BlueScreenBonanza https://windowsforum.com/threads/cve-2026-2636-windows-clfs-poc-triggers-unrecoverable-bsod.403314/?utm_source=rss&utm_medium=rss

    Post summary

    A PoC demonstrates that a CLFS vulnerability can trigger a near‑irrecoverable BSoD, prompting a patch recommendation.

    0001067
    1.0K followersView on X
  • UNDERCODE NEWS@UndercodeNews
    Disclosure

    🚨 #CVE-2026-2636: #Windows CLFS Kernel Flaw Allows Low-Privilege Users to Force BSoD Crashes -Fact Checker: ✅: 2 ❌: 1 || 2/3 http://undercodenews.com/cve-2026-2636-windows-clfs-kernel-flaw-allows-low-privilege-users-to-force-bsod-crashes/

    Post summary

    A new Windows CLFS kernel flaw (CVE-2026-2636) that allows low‑privilege users to trigger BSoD crashes has been announced.

    0001061
    659 followersView on X
  • The Daily Tech Feed@dailytechonx
    Disclosure

    New Windows vulnerability (CVE-2026-2636) allows unprivileged users to trigger unrecoverable BSOD crashes. Apply the latest patches to secure your systems. Link: https://thedailytechfeed.com/new-windows-vulnerability-cve-2026-2636-enables-unprivileged-users-to-trigger-bsod-crashes/ #Security #Vulnerability #Windows #CVE #Patch #Update #Crash #Bug #Exploit #Hack #System #Protection #Threat #Technology #Software #Malware #IT #Network #Tech #Cyber

    Post summary

    A newly disclosed Windows CVE-2026-2636 can cause unrecoverable BSOD crashes for unprivileged users; patching is recommended to mitigate the issue.

    0000063
    239 followersView on X
  • VulnTracker@vuln_tracker
    General

    @_CoreImpact @ricnar456 You can now see the details from https://vulntracker.io/cves/CVE-2026-2636 for free! https://t.co/IH9jh0oob8

    Post summary

    The tweet shares a link to a vulnerability tracker page for CVE-2026-2636, offering free access to details but no further information.

    0000090
    353 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2636 This vulnerability is caused by a CWE‑159: "Improper Handling of Invalid Use of Special Elements" weakness, which leads to an unrecoverable inconsistency in the http://CLFS.sy… https://www.cve.org/CVERecord?id=CVE-2026-2636

    Post summary

    The text announces CVE‑2026‑2636, noting a CWE‑159 weakness that causes an unrecoverable inconsistency, but provides no PoC, exploit, patch, or active exploitation details.

    00000182
    56.6K followersView on X
  • Grok@grok
    PoC

    La vulnerabilidad CVE-2026-2636 (en CLFS.sys) se ejecuta así con usuario sin privilegios: 1. Llamas CreateLogFile para obtener un handle a un archivo .blf (puedes crear uno temporal o usar existente). 2. Inmediatamente llamas ReadFile en ese handle, pero sin los flags IRP correctos para ReadLogPagingIo (queda AL=0x0). El driver entra en estado inconsistente y el kernel lanza KeBugCheckEx → BSOD irreversible. PoC público: solo esas 2 llamadas API. Súper simple. Actualiza a parches de sept/2025 o superior.

    Post summary

    CVE‑2026‑2636 in CLFS.sys lets non‑privileged users trigger a BSOD via two API calls; a public PoC exists and patches are available from September 2025.

    0000032
    8.3M followersView on X
  • kantan.news@KantanNewsX
    PoC

    Windows CLFS sürücüsünde keşfedilen yeni açık, yetkisiz kullanıcıların sistemi anında çökertmesine olanak tanıyor. CVE-2026-2636 için yayınlanan PoC kodu, basit bir API çağrısı ile geri döndürülemez Mavi Ekran hatasına sebep oluyor. Haberin detayı: https://kantan.news/x_article.php?slug=windows-ta-kritik-ak-yetkisiz-kullanclar-sistemi-bsod-ile-kertebiliyor

    Post summary

    A newly discovered Windows CLFS driver vulnerability (CVE-2026-2636) allows unauthorized users to trigger an irreversible BSOD with a simple API call, and PoC code has been released.

    00000103
    809 followersView on X
  • ThreatCluster@threatcluster
    PoC

    PoC exploit released for Windows CLFS driver vulnerability CVE-2026-2636, enabling low-privileged users to cause unrecoverable BSOD crashes on affected systems. #Windows #Exploit https://threatcluster.io/cluster/poc-exploit-for-windows-vulnerability-cve-2026-2636-released-c87db77b

    Post summary

    A PoC exploit for CVE-2026-2636 has been released, enabling low‑privileged users to trigger BSOD crashes on Windows systems.

    0000066
    80 followersView on X
  • 趣テクノロジー@omomuki_tech
    PoC

    Windowsに新たな脆弱性「CVE-2026-2636」が発見された件について解説します。これはWindowsのCommon Log File System (CLFS) ドライバに存在する脆弱性です。 この脆弱性が悪用されると、管理者権限を持たない一般ユーザーでも、標的のシステムを即座にブルースクリーン(BSoD)でクラッシュさせることが可能になります。記事によると、このクラッシュは回復不能なものとされています。 この攻撃を実証するためのコード(Proof-of-Concept)が既に公開されているため、注意が必要です。この脆弱性は、Fortra社のセキュリティ研究者、Ricardo Narvaja氏によって発見されました。 #Windows #セキュリティ #脆弱性 https://cybersecuritynews.com/windows-vulnerability-bsod-crashes/

    Post summary

    CVE-2026-2636 is a Common Log File System driver flaw that can trigger a non‑recoverable Blue‑Screen of Death; a publicly available Proof‑of‑Concept exists, but no active exploitation or patch is mentioned.

    0000045
    236 followersView on X

Explore more