CVE-2026-72971Active Exploitation(microsoft / windows_11_26h1)

MEDIUMCVSS 5.5 · MEDIUM

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch microsoft windows_11_26h1 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_11_26h1

Threat summary

  • Active exploitation appears in 7 classified signals
  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 7 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 8 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 4 mentions (2026-08-11); latest day: 1
  • 9 total mentions across 4 days

Affected systems

Vendors
Products
windows_11_26h1

Deep dive

Activity timeline9 mentions / 4d
01234Mentions · 2026-08-11: 4Mentions · 2026-08-13: 3Mentions · 2026-08-17: 1Mentions · 2026-08-18: 1Active Exploitation · 2026-08-11: 3Active Exploitation · 2026-08-13: 2Active Exploitation · 2026-08-17: 1Active Exploitation · 2026-08-18: 1Patch / Workaround · 2026-08-11: 2Patch / Workaround · 2026-08-13: 1Patch / Workaround · 2026-08-17: 1Technical Details · 2026-08-11: 3Technical Details · 2026-08-13: 3Technical Details · 2026-08-17: 1Technical Details · 2026-08-18: 108-1108-1308-1708-18
Signal classification2 categories
Active Exploitation
666.7%
Disclosure
333.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-114
Active Exploitation3Disclosure1
2026-08-133
Active Exploitation2Disclosure1
2026-08-171
Disclosure1
2026-08-181
Active Exploitation1
Full discourse9 posts
  • National CERT/CC@CERT_UG
    Active Exploitation

    🚨 August 13 Patch Advisories Cisco ASA and FTD (CVE-2026-20349): actively exploited, no patch yet. One request crashes your VPN gateway. Windows DNS Server (CVE-2026-62878, CVSS 9.8): unauthenticated RCE, no credentials needed. Windows Container Driver (CVE-2026-72971). https://t.co/oVbQUMBJjk

    Post summary

    Three CVEs are highlighted: CVE‑2026‑20349, actively exploited in Cisco ASA/FTD, CVE‑2026‑62878 grants unauthenticated RCE in Windows DNS, and CVE‑2026‑72971 is mentioned with no details. No patches or PoC code are provided.

    02040315
    1.5K followersView on X
  • Horizon Secured@horizon_secured
    Active Exploitation

    🚨 𝗛𝗼𝗿𝗶𝘇𝗼𝗻 𝗔𝗹𝗲𝗿𝘁 – 𝗔𝘂𝗴𝘂𝘀𝘁 𝟮𝟬𝟮𝟲 𝗣𝗮𝘁𝗰𝗵 𝗧𝘂𝗲𝘀𝗱𝗮𝘆 August Patch Tuesday is here, and we have 𝟯 𝗻𝗲𝘄 𝘇𝗲𝗿𝗼-𝗱𝗮𝘆𝘀 and 𝟲 vulnerabilities with a CVSS score of 9.0+. 𝗭𝗲𝗿𝗼-𝗗𝗮𝘆𝘀 🔸 CVE-2026-68820 – Windows Ancillary Function Driver for WinSock Elevation of Privilege 🔸 CVE-2026-72971 – Windows Container Isolation FS Filter Driver Tampering 🔸 CVE-2026-62832 – Windows User Profile Service Elevation of Privilege Of those, 𝗖𝗩𝗘-𝟮𝟬𝟮𝟲-𝟲𝟴𝟴𝟮𝟬 is already being exploited in the wild and can lead to SYSTEM privileges. And among the 9.0+ vulnerabilities, we have multiple unauthenticated network RCEs, including Windows DNS Server, Windows Deployment Services TFTP Server, and Windows iSCSI Target Service. Full breakdown coming in this month’s Horizon Alert. #PatchTuesday #CyberSecurity #ZeroDay #Vulnerability #Microsoft

    Post summary

    The alert reports that CVE‑2026‑68820 is being used in the wild, while noting additional zero‑day and RCE vulnerabilities affecting Windows services.

    00041392
    2.7K followersView on X
  • Action1@Action1corp
    Active Exploitation

    Still sorting through Patch Tuesday? A few vulnerabilities deserve a closer look. In his August Patch Tuesday coverage for Infosecurity Magazine, Phil Muncaster looks at some of the vulnerabilities that stood out this month. Mike Walters highlights CVE-2026-68820 as a priority for organizations. It’s already being exploited in the wild and could give attackers elevated privileges and broad control over a Windows system. Jack Bicer also looks at two publicly disclosed vulnerabilities: CVE-2026-62832, which could expose another user’s data and lead to admin privileges, and CVE-2026-72971, a Windows Container Isolation flaw tied to improper file access handling. If you’re still working through August’s patching priorities, this is worth a read. https://hubs.ly/Q04tqLwT0 #PatchTuesday #Patching #Action1

    Post summary

    The article notes that CVE‑2026‑68820 is already being exploited to gain elevated privileges, while also providing details on other August Patch Tuesday CVEs. It urges organizations to prioritize patching these vulnerabilities.

    00010103
    618 followersView on X
  • Human Firewall@HumanFirewallHQ
    Disclosure

    Two more zero-days were public before yesterday: CVE-2026-62832 — User Profile Service link-following, a.k.a. "LegacyHive". Microsoft rates exploitation MORE LIKELY. Local creds → another user's hive → admin. CVE-2026-72971 — unionfs.sys container filter (less likely).

    Post summary

    Two zero‑day vulnerabilities, CVE‑2026‑62832 and CVE‑2026‑72971, have been publicly disclosed, with Microsoft noting higher exploitation likelihood for the former.

    1000058
    2 followersView on X
  • Tako@tac0tech
    Active Exploitation

    Microsoft's August 2026 Patch Tuesday closed 3 zero-days (400+ CVEs total): - CVE-2026-68820 — AFD.sys (WinSock) — actively exploited - CVE-2026-62832 — Windows User Profile Service — publicly disclosed - CVE-2026-72971 — Container Isolation FS Filter Driver — publicly disclosed

    Post summary

    Microsoft’s August 2026 Patch Tuesday addressed three zero‑day CVEs, one of which (CVE‑2026‑68820) was reportedly actively exploited in the wild, prompting the release of a patch.

    0001089
    5 followersView on X
  • Xavier Rivera@XavierRiveraX
    Active Exploitation

    Microsoft's August Patch Tuesday fixed 400 flaws, including 3 Windows zero-days, all local privilege-escalation bugs needing no user interaction: • CVE-2026-68820: AFD.sys WinSock flaw, already exploited by Lazarus to deploy the FudModule rootkit • CVE-2026-62832: User Profile Service flaw ('LegacyHive'), publicly disclosed • CVE-2026-72971: Container Isolation filter driver flaw, publicly disclosed 42 of the 400 fixes are rated Critical. Patch now.

    Post summary

    Microsoft announced a Patch Tuesday update for 400 flaws, including three zero-days, one of which has been actively exploited by Lazarus. The update emphasizes the need for immediate patching of local privilege‑escapable vulnerabilities.

    00010104
    599 followersView on X
  • BT Haberler@BTHaberler
    Disclosure

    Microsoft'un Ağustos Yaması Final Raporunda 421 Açık ve İki Ek Sıfır Gün Ortaya Çıktı Daha önce duyurduğumuz Microsoft Ağustos yamasının resmi final raporunda toplam açık sayısı 398'den 421'e yükseldi ve Lazarus'un istismar ettiği CVE-2026-68820'nin yanında iki yeni sıfır gün açığı daha ortaya çıktı! • "LegacyHive" olarak adlandırılan CVE-2026-62832, kullanıcı profil hizmetinde; CVE-2026-72971 ise konteyner sürücüsünde yetki yükseltmesine yol açıyor. • Ayrıca CVSS 9.8'lik dört kritik uzaktan kod yürütme açığı ve Exchange'de kimlik doğrulamayı atlatmaya izin veren CVE-2026-62911 de bu ayki yamada kapatıldı. Bir Patch Tuesday raporunun ilk yayınlanmasından günler sonra bile açık sayısının ve sıfır gün listesinin güncellenmeye devam etmesi, bu ölçekteki güvenlik güncellemelerinin tam kapsamının ortaya çıkmasının zaman alabildiğini gösteriyor. #SiberGüvenlik #Microsoft #PatchTuesday

    Post summary

    The August final patch report details 421 CVEs—including new zero‑day vulnerabilities—and confirms Lazarus exploitation of CVE‑2026‑68820, noting that all issues were addressed in the latest patch.

    0000053
    39 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-72971 Local Tampering in Windows Container Isolation FS Filter Driver via Improper Link Resolution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-72971

    Post summary

    A new local tampering vulnerability (CVE‑2026‑72971) was disclosed, affecting the Windows Container Isolation FS Filter Driver through improper link resolution.

    00000114
    4.1K followersView on X
  • FactoryInternet@FactoryInternet
    Active Exploitation

    Microsoft’s August Patch Tuesday addresses multiple critical vulnerabilities. Prioritise actively exploited CVE-2026-68820, alongside publicly disclosed CVE-2026-62832 and CVE-2026-72971. Review, test and patch promptly: https://zurl.co/nK5AE #PatchTuesday #MSSP #SOC

    Post summary

    Microsoft's August Patch Tuesday stresses that CVE‑2026‑68820 is actively exploited and should be prioritized. The advisory also covers CVE‑2026‑62832 and CVE‑2026‑72971, urging timely patching.

    00000208
    252 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64

Explore more