Brand ClaimErleben, was verbindet

Advisory 2026-2711 - Microsoft Windows Products: Multiple Vulnerabilities

Notice: You can now also find information from the Vulnerability Advisory Service in the CTI portal!
The CTI portal is available at the following address: https://cti-portal.telekom.net/advisories/2026-2711

Date

2026-08-12

State

2026-08-14

Risk*

Damage: HIGH
Attack Probability: MEDIUM-HIGH

Attack

An attacker can exploit multiple vulnerabilities in Microsoft Windows Server 2012, Microsoft Windows Server 2012 R2, Microsoft Windows Server 2016, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows Server 2022, Microsoft Exchange, Microsoft Windows 11, Microsoft Windows Server 2025 and Microsoft Windows in order to execute arbitrary code, in order to elevate his privileges, in order to create a Denial of Service condition, in order to disclose information, in order to manipulate files, in order to carry out a Cross-Site Scripting attack, and in order to bypass security measures.

Notice: Further details on this vulnerability advisory is available to registered customers after having logged in or via our daily advisory email.

* The probability of an attack is determined by the attacker's motivation, the necessary expend and the possibilities for an attack. The damage probability is determined by the expend needed to resolute the attack and probable indirecte consequences of an attack for business processes. Telekom Security assumes worst case scenarios.

Copyright © 1999-2026 Deutsche Telekom Security GmbH. All rights reserved. Reproduction and distribution of this publication in any form - even in parts - without prior written permission is forbidden.

The information contained herein has been obtained from sources believed to be reliable and trusted or have been verified. Telekom Security can take liability for completeness, accuracy and correctness only in so far, as gross negligence or intention create liability. Any liability beyond it, in particular possible damages resulting from using or non-usability of the information contained herein, is excluded.