Windows Kernel Security Feature Bypass Vulnerability
MonitorCVSS 5.5CVE-2026-58614Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
An out-of-bounds read in the Windows Kernel allows an authorized local attacker to bypass a security feature. All versions of Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 are affected. Exploitation is assessed as unlikely. The vulnerability is fixed in July 2026 security updates for each platform.
What this means
What could happen
An attacker with local access to a Windows system could read kernel memory to bypass a security feature, potentially enabling privilege escalation or other attacks. This is a local threat and does not directly impact remote operations.
Who's at risk
This affects organizations running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025. HMIs (Human Machine Interfaces), engineering workstations, and Windows-based SCADA servers that have local user access should be updated. Organizations using Windows in air-gapped or disconnected OT networks should prioritize systems that can be updated during maintenance windows.
How it could be exploited
An attacker with a valid local account on a Windows workstation or server reads out-of-bounds kernel memory to circumvent a security control. This requires interactive access to the machine and does not provide direct remote operations impact but could enable subsequent attacks.
Prerequisites
- Local user account on the affected Windows system
- Ability to execute code or run a crafted application on the system
Local access required (limits risk in typical OT network architectures)Low EPSS score (0.3%, unlikely to be exploited)Not actively exploited (KEV status: No)
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the July 2026 Microsoft security update to your Windows systems
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/dc56a9d5-f6fd-4add-9c4a-3248082e6b51Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.