All CVEs
Vulnerability intelligence

CVE-2026-33694

CWE-59

This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially facilitates arbitrary code execution, whereby an attacker may exploit the vulnerability to execute malicious code with elevated SYSTEM privileges.

CVSS Score
7.4
High
EPSS — Exploit Probability
0.1%
Riskier than 4% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered Apr 24, 2026 · latest Apr 24, 2026

Coverage timeline