CVE-2026-50416: Win32k Information Disclosure Vulnerability
Published Jul 14, 2026
·Updated
Exposure of sensitive information to an unauthorized actor in Windows Win32K allows an authorized attacker to disclose information locally.
Other sources
Win32k Information Disclosure Vulnerability
— Microsoft
Affected Software
15 affected componentsFixes available
Microsoft Windows 11=25H2
10.0.26200.8875
Microsoft Windows 11=26H1
10.0.28000.2525
Microsoft Windows 11=26H1
10.0.28000.2525
Microsoft Windows Server 2025<10.0.26100.33158
10.0.26100.33158
Microsoft Windows Server 2025<10.0.26100.33158
10.0.26100.33158
Microsoft Windows 11=25H2
10.0.26200.8875
Microsoft Windows 11=24H2
10.0.26100.8875
Microsoft Windows 11=24H2
10.0.26100.8875
Microsoft Windows 11 24h2<10.0.26100.8875
Microsoft Windows 11 24h2<10.0.26100.8875
Microsoft Windows 11 25h2<10.0.26200.8875
Microsoft Windows 11 25h2<10.0.26200.8875
Microsoft Windows 11 26h1<10.0.28000.2525
Microsoft Windows 11 26h1<10.0.28000.2525
Microsoft Windows Server 2025<10.0.26100.33158
Remediation
Event History
Jul 14, 2026
CVE Published
via Microsoft·02:00 PM
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:06 PM
Data Sourced
via MITRE·05:06 PM
DescriptionSeverity
Data Sourced
via NVD·06:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-50416?
The severity of CVE-2026-50416 is categorized as low with a score of 3.3.
2
How do I fix CVE-2026-50416?
To fix CVE-2026-50416, you should apply the latest security updates provided by Microsoft for Windows 11 and Windows Server 2025.
3
What does CVE-2026-50416 affect?
CVE-2026-50416 affects Microsoft Windows 11 and Microsoft Windows Server 2025.
4
What type of vulnerability is CVE-2026-50416?
CVE-2026-50416 is classified as an information disclosure vulnerability.
5
Who is affected by CVE-2026-50416?
Authorized attackers with local access can exploit CVE-2026-50416 to disclose sensitive information.