Medium severity5.5NVD Advisory· Published Aug 11, 2026· Updated Aug 14, 2026
CVE-2026-72971
CVE-2026-72971
Description
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
Affected products
3cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*+ 1 more
- cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*range: <10.0.28000.2704
- cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*range: <10.0.28000.2704
Patches
Vulnerability mechanics
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72971nvdVendor AdvisoryPatch
News mentions
12- Cyber Security Weekly Newsletter – Outlook RCE, Palo Alto, Cisco 0-day and Windows 0-Day Flaws +20 StoriesCyber Security News · Aug 16, 2026
- Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)Help Net Security · Aug 12, 2026
- Microsoft Fixes 400 Flaws on August Patch TuesdayInfosecurity Magazine · Aug 12, 2026
- ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM AccessThe Hacker News · Aug 12, 2026
- Microsoft Plugs Nearly 400 Security HolesKrebs on Security · Aug 11, 2026
- Patch Tuesday - August 2026Rapid7 Blog · Aug 11, 2026
- August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-DaySecurityWeek · Aug 11, 2026
- Microsoft's August 2026 Patch Tuesday addresses 398 CVEs (CVE-2026-68820)Tenable Blog · Aug 11, 2026
- Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)SANS Internet Storm Center · Aug 11, 2026
- Microsoft Patch Tuesday Update August 2026 – 394 Vulnerabilities Fixed, Including 3 Zero-DaysCyber Security News · Aug 11, 2026
- Windows 11 26h1: 25 Vulnerabilities Patched, Including Actively Exploited Privilege Escalation FlawVypr Intelligence · Aug 11, 2026
- August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEsCrowdStrike Blog