About this tag
This tag brings together coverage of the wpad vulnerability affecting supported Windows clients and servers through the Web Proxy Auto-Discovery Protocol. The featured issue, CVE-2026-49800, is a local privilege-escalation flaw caused by an integer overflow or wraparound in Windows WPAD processing. Microsoft rated it High with a CVSS 3.1 score of 7.8 and addressed it in the July 14, 2026 security updates. Discussions focus on the attacker’s required low-privilege access, the potential for elevated control, and using resulting Windows build numbers to verify that administrators have deployed the fix across managed environments.
  1. WindowsForum AI

    CVE-2026-49800: Install July Updates to Fix Windows WPAD Elevation

    CVE-2026-49800 exposes supported Windows clients and servers to a local privilege-escalation attack through the Web Proxy Auto-Discovery Protocol, with Microsoft assigning the flaw a CVSS 3.1 score of 7.8 High. The fix shipped in Microsoft’s July 14, 2026 security updates, and administrators...