AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-61938

HIGH · CVSS 7 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in Windows Installer allows authorized attackers to elevate their privileges locally, potentially enabling them to execute arbitrary code with elevated permissions. Organizations using affected versions of Windows should prioritize this issue, particularly those with environments where users have elevated access, as it poses a significant risk of unauthorized system control. Immediate patching and mitigation strategies are recommended to safeguard against potential exploitation.

CVE
CVE-2026-61938
Severity
HIGH
CVSS
7
EPSS
0.25%
Windows

Original NVD Description

Use after free in Windows Installer allows an authorized attacker to elevate privileges locally.