VDB

CVE-2026-57087

CVE-2026-57087 PUBLISHED CVSS 8.8 HIGH

Reported by microsoft · Published July 14, 2026

Heap-based buffer overflow in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

Risk Scores

CVSS 3.1
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Affected Products

VendorProductVersions
MicrosoftWindows 10 Version 160710.0.14393.0
MicrosoftWindows 10 Version 180910.0.17763.0
MicrosoftWindows 10 Version 21H210.0.19044.0
MicrosoftWindows 10 Version 22H210.0.19045.0
MicrosoftWindows 11 Version 24H210.0.26100.0
MicrosoftWindows 11 Version 25H210.0.26200.0
MicrosoftWindows 11 version 26H110.0.28000.0
MicrosoftWindows Server 201610.0.14393.0
MicrosoftWindows Server 2016 (Server Core installation)10.0.14393.0
MicrosoftWindows Server 201910.0.17763.0
MicrosoftWindows Server 2019 (Server Core installation)10.0.17763.0
MicrosoftWindows Server 202210.0.20348.0
MicrosoftWindows Server 202510.0.26100.0
MicrosoftWindows Server 2025 (Server Core installation)10.0.26100.0
microsoftwindows_server_201610.0.14393.0, 10.0.14393.0, 10.0.14393.0
microsoftwindows_10_21H210.0.19044.0, 10.0.19044.0, 10.0.19044.0
MicrosoftWindows 10 Version 22H210.0.19045.0, 10.0.19045.0, 10.0.19045.0
MicrosoftWindows Server 201610.0.14393.0, 10.0.14393.0, 10.0.14393.0
microsoftwindows_11_25H210.0.26200.0, 10.0.26200.0, 10.0.26200.0
MicrosoftWindows Server 2016 (Server Core installation)10.0.14393.0, 10.0.14393.0, 10.0.14393.0

…and 19 more

Timeline

  • Jul 14, 2026 CVE Published
  • Jul 15, 2026 Coalition ESS Score
  • Jul 16, 2026 Security Advisory
  • Jul 22, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score
  • Aug 20, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›