CVE-2026-49792 Details
Description
Numeric truncation error in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
A numeric truncation error in the Windows Resilient File System (ReFS) has been identified, allowing an authorized attacker to execute code locally. This vulnerability affects multiple Windows products, including Windows Server 2016, Windows 10 versions 21H2, 22H2, and 1809, as well as Windows 11 versions 24H2 and 26H1. The vulnerability arises from a numeric truncation error, which can be exploited to execute arbitrary code on the affected system.
Users can download the security update for this vulnerability via the Microsoft Update Catalog. Security Update KB5099535 is available for Windows Server 2016 and Windows 10 Version 1607. For Windows 11, Security Update KB5101649 is available for Version 26H1 on ARM64-based Systems, and KB5095051 for Version 26H1 on x64-based Systems. Windows 11 Version 24H2 for ARM64 and x64-based Systems also has a corresponding security update, KB5101650. Windows Server 2025 and Windows Server 2022 users can also apply the relevant security updates. For Windows 10 Version 22H2, Security Update KB5099539 is available for 32-bit, ARM64-based, and x64-based Systems. Windows 10 Version 21H2 for x64 and ARM64-based Systems, as well as Version 21H2 for 32-bit Systems, also have available security updates.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49792 | [email protected] | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-197 | Numeric Truncation Error | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft windows 10 1607 | < 10.0.14393.9339 |
CPE
Remediation
| |
| microsoft windows 10 1809 | < 10.0.17763.9020 |
CPE
Remediation
| |
| microsoft windows 10 21h2 | < 10.0.19044.7548 |
CPE
Remediation
| |
| microsoft windows 10 22h2 | < 10.0.19045.7548 |
CPE
Remediation
| |
| microsoft windows 11 24h2 | < 10.0.26100.8875 |
CPE
Remediation
| |
| microsoft windows 11 25h2 | < 10.0.26200.8875 |
CPE
Remediation
| |
| microsoft windows 11 26h1 | < 10.0.28000.2269 < 10.0.28000.2525 |
CPE
Remediation
| |
| microsoft windows server 2016 | < 10.0.14393.9339 |
CPE
Remediation
| |
| microsoft windows server 2019 | < 10.0.17763.9020 |
CPE
Remediation
| |
| microsoft windows server 2022 | < 10.0.20348.5386 |
CPE
Remediation
| |
| microsoft windows server 2025 | < 10.0.26100.33158 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Modified | [email protected] |
| Jul 20, 2026 | Initial Analysis | [email protected] |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | [email protected] |