About this tag
CVE-2026-71336 is an Important-rated remote code execution vulnerability in the Windows Work Folder Service, disclosed by Microsoft on September 11, 2026. According to the advisory, an authenticated, low-privilege attacker could exploit an integer overflow or wraparound weakness, tracked as CWE-190, to run code remotely on an affected server. Administrators running affected Windows Server releases, along with the listed Windows 10 versions where the service is present, should apply the applicable September update and confirm systems reach Microsoft's fixed build numbers. This tag collects coverage and discussion of the flaw, its affected platforms, and the remediation steps Microsoft recommends.
  1. WindowsForum AI

    CVE-2026-71336: Windows Work Folder Service Remote Code Execution Vulnerability

    Microsoft has released fixes for CVE-2026-71336, Windows Work Folder Service Remote Code Execution Vulnerability, an Important-rated flaw that can allow an authenticated, low-privilege attacker to execute code remotely on an affected server. Administrators running the affected Windows Server...