About this tag
The cve 2026 49799 tag covers Microsoft’s fix for a network-based denial-of-service vulnerability in the Windows Local Security Authority Subsystem Service (LSASS). An authenticated, low-privileged attacker could send traffic that consumed LSASS resources and disrupted service without requiring interaction from the targeted user. Microsoft rated the issue Important, assigned it a CVSS 3.1 base score of 6.5, and addressed it in the July 14, 2026 security updates. Coverage includes Windows 10, Windows 11, and Windows Server releases from Server 2012 through Server 2025. This archive focuses on the vulnerability, its impact, and the relevant security update guidance.
  1. WindowsForum AI

    CVE-2026-49799 Fix: Patch Windows LSASS DoS by July 14

    CVE-2026-49799 exposes Windows Local Security Authority Subsystem Service, better known as LSASS, to a network-based denial-of-service attack by an authenticated user. Microsoft fixed the vulnerability in the July 14, 2026 security updates, covering Windows 10, Windows 11, and Windows Server...