SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-49174

MEDIUM · CVSS 6.1 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

A vulnerability in Microsoft Windows DNS allows an authorized attacker to exploit missing authentication for critical functions, enabling local tampering of DNS records. This could lead to unauthorized changes in network configurations, potentially compromising data integrity and availability. Organizations using affected Windows versions should prioritize patching to mitigate the risk of local attacks.

CVE
CVE-2026-49174
Severity
MEDIUM
CVSS
6.1
EPSS
0.20%
Microsoft Windows

Original NVD Description

Missing authentication for critical function in Microsoft Windows DNS allows an authorized attacker to perform tampering locally.

Related CVEs

Other vulnerabilities affecting the same vendor(s)