Vulnerability · NVD
CVE-2026-50508
MEDIUM 6.5
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
Attack vector : Network
No privileges required
Show raw CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
8.68%
above median
percentile 94.6%
OS versions that fix this CVE
This CVE is resolved by the following OS security releases. Update the OS to at least the listed version.
- Windows Server 2022 Fixed in 10.0.20348.5256
- Windows Server 2016 Fixed in 10.0.14393.9234
- Windows 11 22H2 · 2022-H2 Fixed in 10.0.22631.7219
- Windows 10 1607 · 2016-07 Fixed in 10.0.14393.9234