CVE-2026-62772Disclosure(microsoft / windows_11_26h1)

LOWCVSS 7.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_11_26h1 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Heap-based buffer overflow in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to elevate privileges locally.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_11_26h1

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
windows_11_26h1

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-12: 3Patch / Workaround · 2026-08-12: 1Technical Details · 2026-08-12: 208-12
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets2 URLs
Full discourse3 posts
  • Mohi@disismohi
    Disclosure

    CVE-2026-62772: heap overflow in Windows container isolation driver (unionfs.sys). Authorized attacker → SYSTEM. If you run Windows nodes, here's what I'd check Wednesday.

    Post summary

    The post announces a heap overflow in Windows container isolation driver unionfs.sys that could let an authorized attacker reach SYSTEM privileges, but no PoC, tool, active exploitation, or patch details are provided.

    1000059
    74 followersView on X
  • Mohi@disismohi
    General

    Wednesday action: run the driver check, queue a node pool rotation if you're patched, or schedule the Linux migration conversation you've been postponing. https://nvd.nist.gov/vuln/detail/CVE-2026-62772

    Post summary

    The post merely references CVE-2026-62772 via a NVD link and offers no technical specifics, PoC, exploit, or mitigation details.

    0000040
    74 followersView on X
  • Windows Forum@windowsforum
    Patch

    🛡️ Windows container hosts have a privilege-escalation flaw in unionfs.sys. Patch every Server, Kubernetes, and dev host—because “containerized” shouldn’t mean “security optional.” https://windowsforum.com/security-alerts.84/cve-2026-62772-patch-windows-container-host-privilege-flaw.442622/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #WindowsSecurity #ContainerSecurity #PatchTuesday #Cve202662772 https://t.co/d4LIO2NuzV

    Post summary

    The tweet announces a privilege‑escalation flaw in unionfs.sys affecting Windows container hosts and urges immediate patching.

    0000043
    1.3K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64

Explore more