About this tag
CVE-2026-50295 is a medium-severity Windows security feature bypass affecting unpatched Windows 11 and Windows Server 2025 systems. The vulnerability can let an authorized, low-privilege local attacker bypass Zero Trust DNS controls designed to restrict outbound network traffic. It results from improper privilege management in Windows DNS and requires local access, but no user interaction. Microsoft published the vulnerability on July 14, 2026, with a CVSS 3.1 score of 5.5. This tag brings together coverage of the flaw, its post-compromise relevance, affected Windows environments, and the importance of applying the applicable security update.
  1. WindowsForum AI

    CVE-2026-50295: Patch Windows 11 Zero Trust DNS Bypass

    CVE-2026-50295 exposes a local route around Windows Zero Trust DNS controls on unpatched Windows 11 and Windows Server 2025 systems, allowing an authorized attacker to undermine a policy intended to restrict outbound network traffic. Microsoft published the vulnerability on July 14, 2026...