Cyber Resilience

CVE-2026-26151

Microsoft Windows 10 21H2 ≤ 10.0.19044.7184

Published
14 April 2026
Modified
26 May 2026
Patch / advisory
CVSS Score v3.1 7.1
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
EPSS Score 0.0083 54th percentile
Risk Priority 55 floored blend · peak EPSS

Summary

CVE-2026-26151 is a high-severity Insufficient UI Warning of Dangerous Operations (CWE-357) vulnerability in Microsoft Windows 10 21H2. Its CVSS base score is 7.1 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique User Execution (T1204); ranked in the top 46% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2026-26151 is a vulnerability in Windows Remote Desktop stemming from insufficient UI warnings for dangerous operations, which allows an unauthorized attacker to perform spoofing over a network. Published on 2026-04-14, it carries a CVSS v3.1 base score of 7.1 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N) and maps to CWE-357.

The attack requires no privileges and can be launched over the network with low complexity, though it demands user interaction. Successful exploitation enables high-impact confidentiality violations alongside low-impact integrity alterations, such as spoofing to trick users into disclosing sensitive information.

For mitigation guidance and patch details, refer to the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26151.

EU & UK References

Vulnerability Data

Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise Techniques

T1204 User Execution Execution
An adversary may rely upon specific actions by a user in order to gain execution.
T1204.001 Malicious Link Execution
An adversary may rely upon a user clicking a malicious link in order to gain execution.
T1204.002 Malicious File Execution
An adversary may rely upon a user opening a malicious file in order to gain execution.
Derived from this CVE’s CWE(s) via the direct CWE→ATT&CK cross-walk.

CVEs Like This One

CVE-2025-33054Same product: Microsoft Windows 11 23H2
CVE-2025-47967Same vendor: Microsoft
CVE-2024-49054Same vendor: Microsoft
CVE-2024-43505Same vendor: Microsoft
CVE-2024-29057Same vendor: Microsoft
CVE-2026-58597Same vendor: Microsoft
CVE-2024-26188Same vendor: Microsoft
CVE-2024-21387Same vendor: Microsoft
CVE-2024-43580Same vendor: Microsoft
CVE-2024-21336Same vendor: Microsoft

Affected Assets

microsoft
windows 10 1607
≤ 10.0.14393.9060 · ≤ 10.0.14393.9060
microsoft
windows 10 1809
≤ 10.0.17763.8644 · ≤ 10.0.17763.8644
microsoft
windows 10 21h2
≤ 10.0.19044.7184 · ≤ 10.0.19044.7184 · ≤ 10.0.19044.7184
microsoft
windows 10 22h2
≤ 10.0.19045.7184 · ≤ 10.0.19045.7184 · ≤ 10.0.19045.7184
microsoft
windows 11 23h2
≤ 10.0.22631.6936 · ≤ 10.0.22631.6936
microsoft
windows 11 24h2
≤ 10.0.26100.8246 · ≤ 10.0.26100.8246
microsoft
windows 11 25h2
≤ 10.0.26200.8246 · ≤ 10.0.26200.8246
microsoft
windows 11 26h1
≤ 10.0.28000.1836 · ≤ 10.0.28000.1836
microsoft
windows server 2012
all versions, r2
microsoft
windows server 2016
≤ 10.0.14393.9060
+4 more product configuration(s) — see NVD for full list

Mitigating Controls

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure SDLC practices directly encompass designing noticeable UI warnings for risky operations.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

finds

Security testing in development and acceptance validates that dangerous-operation warnings are sufficiently prominent.

prevents

Secure development lifecycle requires usable security prompts and warnings to be designed into the UI.

prevents

Application security requirements include clear, effective user warnings for dangerous operations.

prevents

Secure system architecture and engineering principles address usable security mechanisms such as prominent warnings.

prevents

Secure coding practices include implementing noticeable, effective UI warnings for risky actions.

References