CVE- 2026-50502 is a high-severity remote code execution vulnerability (CVSS 8.0) affecting various versions of Microsoft Windows 10, including multiple updates. It involves the Windows Event Log service, allowing attackers to execute code with stolen low-privilege credentials. A proof-of-concept exploit exists, with no confirmed exploitation in the wild. Microsoft has released patches, and users are advised to update their systems immediately. Additionally, users should block untrusted SMB traffic and monitor Startup folders for suspicious files to mitigate the risk.
CVE-2026-50502: Public PoC Exploit Details Windows Event Log Remote Code Execution
CyberSIXT Evidence Panel
Article by CyberSIXT