Cyber Resilience

CVE-2026-45586

High

Published: 09 June 2026

Published
09 June 2026
Modified
11 June 2026
KEV Added
Patch
CVSS Score v3.1 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0215 79.8th percentile
Risk Priority 17 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2026-45586 is a high-severity Link Following (CWE-59) vulnerability in Microsoft Windows 10 21H2. Its CVSS base score is 7.8 (High).

Operationally, ranked in the top 20.2% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability details

Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

microsoft
windows 10 1607
≤ 10.0.14393.9234 · ≤ 10.0.14393.9234
microsoft
windows 10 1809
≤ 10.0.17763.8880 · ≤ 10.0.17763.8880
microsoft
windows 10 21h2
≤ 10.0.19044.7417 · ≤ 10.0.19044.7417 · ≤ 10.0.19044.7417
microsoft
windows 10 22h2
≤ 10.0.19045.7417 · ≤ 10.0.19045.7417 · ≤ 10.0.19045.7417
microsoft
windows 11 23h2
≤ 10.0.22631.7219 · ≤ 10.0.22631.7219
microsoft
windows 11 24h2
≤ 10.0.26100.8655 · ≤ 10.0.26100.8655
microsoft
windows 11 25h2
≤ 10.0.26200.8655 · ≤ 10.0.26200.8655
microsoft
windows 11 26h1
≤ 10.0.28000.2269 · ≤ 10.0.28000.2269
microsoft
windows server 2012
all versions, r2
microsoft
windows server 2016
≤ 10.0.14393.9234
+3 more product configuration(s) — see NVD for full list

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References