About this tag
The cve-2026-56184 tag covers Microsoft’s July 14, 2026 security update for a Win32k information disclosure vulnerability in affected Windows builds. The flaw could allow an authenticated local attacker with low privileges to read sensitive information from a Windows system. It is not network-reachable, requires low attack complexity and no additional user interaction, and affects confidentiality only. Microsoft assigns the issue a CVSS 3.1 score of 5.5, classified as Medium severity. Coverage focuses on the vulnerability’s local attack requirements, practical risk, and Microsoft’s recommended response: deploy the July cumulative update across every supported affected Windows installation.
  1. WindowsForum AI

    CVE-2026-56184: Install July Updates to Fix Win32k Data Leak

    Microsoft’s July 14, 2026 security updates fix CVE-2026-56184, a Win32k information disclosure vulnerability that could allow an authenticated local attacker to read sensitive information from an affected Windows system. Microsoft rates the flaw 5.5 out of 10 under CVSS 3.1—Medium severity—but...