Critical severity9.8NVD Advisory· Published Aug 11, 2026· Updated Aug 14, 2026
CVE-2026-62815
CVE-2026-62815
Description
Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Microsoft.Native.Quic.MsQuic.OpenSSLNuGet | >= 2.5.3, < 2.5.10 | 2.5.10 |
Microsoft.Native.Quic.MsQuic.SchannelNuGet | >= 2.5.3, < 2.5.10 | 2.5.10 |
Microsoft.Native.Quic.MsQuic.OpenSSLNuGet | < 2.4.19 | 2.4.19 |
Microsoft.Native.Quic.MsQuic.SchannelNuGet | < 2.4.19 | 2.4.19 |
Affected products
11cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*+ 1 more
- cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*range: <10.0.22631.7517
- cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*range: <10.0.22631.7517
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*+ 1 more
- cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*range: <10.0.26100.9106
- cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*range: <10.0.26100.9106
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*+ 1 more
- cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*range: <10.0.26200.9106
- cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*range: <10.0.26200.9106
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*+ 1 more
- cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*range: <10.0.28000.2704
- cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*range: <10.0.28000.2704
- cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*Range: <10.0.20348.5440
- cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*Range: <10.0.26100.33222
Patches
Vulnerability mechanics
References
12- github.com/advisories/GHSA-92f5-vc22-8j33ghsaADVISORY
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62815nvdVendor AdvisoryPatchWEB
- nvd.nist.gov/vuln/detail/CVE-2026-62815ghsaADVISORY
- github.com/microsoft/msquic/commit/583e7d5b509bb0bfa3518482d98879b6eda41ad0ghsaWEB
- github.com/microsoft/msquic/commit/9ff06b71fd4b4d5258361598ada5b24cbc1beb20ghsaWEB
- github.com/microsoft/msquic/commit/e0f55b5fdc9fff0b4465976d066ebd22fb7e2b3bghsaWEB
- github.com/microsoft/msquic/pull/6217ghsaWEB
- github.com/microsoft/msquic/pull/6219ghsaWEB
- github.com/microsoft/msquic/pull/6220ghsaWEB
- github.com/microsoft/msquic/releases/tag/v2.4.19ghsaWEB
- github.com/microsoft/msquic/releases/tag/v2.5.10ghsaWEB
- github.com/microsoft/msquic/security/advisories/GHSA-92f5-vc22-8j33ghsaWEB
News mentions
9- Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)Help Net Security · Aug 12, 2026
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesCisco Talos Intelligence · Aug 11, 2026
- Microsoft's Patch Tuesday Deluge Continues With August UpdatesDark Reading · Aug 11, 2026
- Patch Tuesday - August 2026Rapid7 Blog · Aug 11, 2026
- Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active AttackThe Hacker News · Aug 11, 2026
- August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-DaySecurityWeek · Aug 11, 2026
- Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)SANS Internet Storm Center · Aug 11, 2026
- Microsoft Patch Tuesday Update August 2026 – 394 Vulnerabilities Fixed, Including 3 Zero-DaysCyber Security News · Aug 11, 2026
- August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEsCrowdStrike Blog