THE page discusses CVE-2026-50454, a serious elevation of privilege vulnerability in Microsoft Windows 11, specifically affecting versions 10.0.26100.0, 10.0.26200.0, and 10.0.28000.0. The vulnerability allows for a UAC (User Account Control) bypass, enabling malicious users with local administrator access to execute arbitrary code at a SYSTEM level without consent prompts. The flaw was disclosed by researcher David Carliez, who also published proof-of-concept code.
Microsoft issued patches in the July 2026 update (versions 10.0.26100.8875, 10.0.26200.8875, etc.) to mitigate this issue. The EPSS risk score is 0.4%. Users are advised to update their systems immediately to avoid potential exploitation.