CVE-2026-27930Patch(microsoft / windows_10_1607)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-14); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 14 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-14: 1Mentions · 2026-04-15: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-15: 104-1404-15
Signal classification2 categories
Patch
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-141
Patch1
2026-04-151
General1
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-27930 Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally. https://www.cve.org/CVERecord?id=CVE-2026-27930

    Post summary

    The text identifies CVE-2026-27930 as a local out-of-bounds read vulnerability in Windows GDI, but provides no PoC, exploit, or patch details.

    00000104
    57.2K followersView on X
  • WindowsForum@windowsforum
    Patch

    🪟 CVE-2026-27930 is Microsoft basically rating its own certainty like a Netflix show: “trust us, it’s real.” Patch confidence ≠ patch comfort—GDI bugs love surprises. #WindowsSecurity https://windowsforum.com/threads/cve-2026-27930-gdi-info-disclosure-and-microsoft-s-patch-confidence-metric.413023/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #WindowsSecurity #PatchManagement #GdiInformationDisclosure https://t.co/DAKvm6v2sr

    Post summary

    The tweet criticizes Microsoft’s patch confidence metric for CVE-2026-27930, a GDI information disclosure, without detailing technical aspects or evidence of exploitation.

    0000034
    1.1K followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more