PT-2026-58147 · Microsoft · Windows

CVE-2026-49172

·

Published

2026-07-14

·

Updated

2026-07-23

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows 10 (affected versions not specified) Windows 11 (affected versions not specified) Windows Server 2019 (affected versions not specified) Windows Server 2022 (affected versions not specified) Windows Server 2025 (affected versions not specified)
Description A heap-based buffer overflow exists in the Windows FTP Service. This flaw allows an unauthorized remote attacker to execute arbitrary code and affect the system over a network. A heap-based buffer overflow occurs when a program writes more data to a heap memory block than it can hold, potentially leading to memory corruption.
Recommendations Update Windows 10 to the July 2026 Patch Tuesday release. Update Windows 11 to the July 2026 Patch Tuesday release. Update Windows Server 2019 to the July 2026 Patch Tuesday release. Update Windows Server 2022 to the July 2026 Patch Tuesday release. Update Windows Server 2025 to the July 2026 Patch Tuesday release.

Fix

DoS

RCE

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49172

Affected Products

Windows