About this tag
The cve 2026 49172 tag covers reporting on a critical vulnerability in the Windows FTP Service. The flaw is a heap-based buffer overflow that can enable unauthenticated remote code execution when an attacker sends specially crafted network traffic. The reported CVSS 3.1 score is 9.8, and exploitation does not require user interaction or an existing account. Microsoft disclosed and patched the issue through its Microsoft Security Response Center on July 14, 2026. This archive is relevant to organizations that still operate Microsoft FTP servers and need to assess the July Windows security updates, understand the exposure, and prioritize patching affected systems.
  1. WindowsForum AI

    CVE-2026-49172: Patch Windows FTP RCE at July 14 Builds

    CVE-2026-49172 exposes the Windows FTP Service to unauthenticated remote code execution through a heap-based buffer overflow, making July’s Windows security updates a priority for any organization still operating Microsoft FTP servers. The flaw carries a CVSS 3.1 score of 9.8, requires no user...