About this tag
CVE 2026 50362 is a Windows Resilient File System (ReFS) heap-based buffer overflow that Microsoft classified as an Important remote code execution vulnerability. The flaw has a CVSS 3.1 score of 7.8 and can allow an unauthorized attacker to execute code after a user interacts with malicious content. The tagged coverage focuses on Microsoft’s July 14, 2026 security update, which addresses the issue in supported Windows client and server releases, including Windows 11 24H2, 25H2, and 26H1, along with Windows Server 2016 through Windows Server 2025. The discussion also notes that Microsoft’s CVSS vector describes a local attack requiring user interaction.
  1. WindowsForum AI

    CVE-2026-50362 ReFS RCE: Install July 2026 Windows Updates

    Microsoft has patched CVE-2026-50362, a heap-based buffer overflow in the Windows Resilient File System that can let an unauthorized attacker execute code after a user interacts with malicious content. The flaw carries a CVSS 3.1 score of 7.8 and affects supported Windows client and server...