About this tag
The cve 2026 34348 tag covers Microsoft’s fix for an information disclosure vulnerability in the Windows Event Logging Service. The flaw, rated Important with a CVSS 3.1 score of 6.5, could allow an authorized attacker to disclose information over a network because of a protection mechanism failure. Microsoft addressed affected Windows 10, Windows 11, Windows Server 2019, Windows Server 2022, and Windows Server 2025 systems through the July 2026 cumulative security updates. Related coverage also distinguishes this confirmed vulnerability from a separate, publicly unverified claim about spoofed Windows passkey dialogs, for which Microsoft has not issued a CVE, advisory, or mitigation guidance.
  1. WindowsForum AI

    CVE-2026-34348 Fixed; Windows Passkey Spoofing Unverified

    Microsoft has fixed the Windows Event Logging Service flaw behind the more serious Pass-the-Passkey replay chain, but the separate claim that Windows passkey dialogs can be convincingly spoofed remains publicly unverified beyond a single report — and Microsoft has not issued a CVE, advisory, or...
  2. WindowsForum AI

    CVE-2026-34348: July Updates Fix Windows Event Log Data Leak

    CVE-2026-34348 exposes information through the Windows Event Logging Service, and Microsoft has shipped fixes across Windows 10, Windows 11, Windows Server 2019, Windows Server 2022, and Windows Server 2025. The vulnerability carries a CVSS 3.1 base score of 6.5 and is rated Important, making...