CVE-2026-56186: Windows Secure Channel Information Disclosure Vulnerability
Out-of-bounds read in Windows Schannel allows an authorized attacker to disclose information over a network.
Other sources
Windows Secure Channel Information Disclosure Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.7548Patch KB5099539 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.7548Patch KB5099539 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23291Patch KB5099444 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.26226Patch KB5099445 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.9020Patch KB5099538 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9339Patch KB5099535 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2525Patch KB5101649 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8875Patch KB5101650 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33158Patch KB5099536 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8875Patch KB5101650 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5386Patch KB5099540
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must be authorized and able to reach the affected system over the network. The vulnerability affects listed Windows client and server products that use Schannel.
Does exploitation require user interaction or complex attack conditions?
No user interaction is required, and the attack complexity is rated low. The attacker does need low-level privileges before exploiting the issue.
What is the likely impact if exploitation succeeds?
Successful exploitation can disclose information from the affected system. The supplied severity vector also indicates a high availability impact, while integrity impact is listed as none.