CVE-2026-50357
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
CVSS
7.8
High
EPSS
0.3%
p26
KEV
—
Exploit Today
8
0-100
Published: Jul 14, 2026 · Last modified: Jul 20, 2026 · CWE-197
0.3%EPSS · 30 days0.3%
2026-08-182026-09-14
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-875299.6 CRI38.7%
——12Numeric truncation error in Media in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)6dCVE-2026-785128.8 HIG55.2%
——17Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network.7dCVE-2026-698227.8 HIG24.6%
——7Numeric truncation error in Windows Kerberos allows an authorized attacker to elevate privileges locally.7dCVE-2026-695787.0 HIG10.5%
——3Numeric truncation error in Windows Kernel allows an authorized attacker to elevate privileges locally.1dCVE-2026-695357.8 HIG15.9%
——5Numeric truncation error in Windows Spaceport.sys allows an authorized attacker to elevate privileges locally.7dCVE-2026-695128.0 HIG53.5%
——16Heap-based buffer overflow in Windows Spaceport.sys allows an authorized attacker to elevate privileges over a network.7d