Record summary

CVE-2026-50357 has a selected CVSS score of 7.8 (high).

Description

Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.

Description source: GitHub Advisory

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 15, 2026 · Source: CVE List

Affected products and versions

Showing 12 of 14
ProductSourceVersion rangeStatus
CVE List10.0.14393.0 to < 10.0.14393.9339affected
CVE List10.0.17763.0 to < 10.0.17763.9020affected
CVE List10.0.19044.0 to < 10.0.19044.7548affected
CVE List10.0.19045.0 to < 10.0.19045.7548affected
CVE List10.0.26100.0 to < 10.0.26100.8875affected
CVE List10.0.26200.0 to < 10.0.26200.8875affected
CVE List10.0.28000.0 to < 10.0.28000.2525affected
CVE List10.0.14393.0 to < 10.0.14393.9339affected

Windows Server 2016 (Server Core installation)

Browse Microsoft / Windows Server 2016 (Server Core installation)
CVE List10.0.14393.0 to < 10.0.14393.9339affected
CVE List10.0.17763.0 to < 10.0.17763.9020affected

Windows Server 2019 (Server Core installation)

Browse Microsoft / Windows Server 2019 (Server Core installation)
CVE List10.0.17763.0 to < 10.0.17763.9020affected
CVE List10.0.20348.0 to < 10.0.20348.5386affected

References

2