Windows NTLM Spoofing Vulnerability in Microsoft Products
CVE-2026-50508
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 9 June 2026
What is CVE-2026-50508?
The vulnerability in Windows NTLM permits unauthorized actors to access sensitive information, enabling potential spoofing attacks across the network. This security flaw highlights the need for immediate attention to protect against unauthorized access and maintain the integrity of user data. Users and administrators are encouraged to apply mitigations and updates provided by the vendor to safeguard against these risks.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9234
Windows 11 version 22H2 ARM64-based Systems 10.0.22621.0 < 10.0.22631.7219
Windows Server 2012 (Server Core installation) x64-based Systems 6.2.9200.0 < 6.2.9200.26132
References
EPSS Score
8% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved