Description
Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.
Published: 2026-07-14
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper certificate validation in Windows Cryptographic Services enables an unauthorized attacker to bypass a security feature over a network. This flaw is classified as CWE‑295 and could allow attackers to present forged or otherwise invalid certificates to the operating system, potentially leading to impersonation or man‑in‑the‑middle attacks against services that rely on certificate validation. The impact is an authentication bypass that undermines the integrity of secure communications.

Affected Systems

Affected systems include Microsoft Windows 10 21H2 and 22H2, Windows 11 24H2, 25H2, and 26H1, as well as Windows Server 2022 and Windows Server 2025 (including Server Core installations). All versions listed in the vendor’s advisory are impacted, and no newer versions were reported as unused.

Risk and Exploitability

The CVSS score of 4.2 indicates a low to moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, further indicating limited current exploitation activity. Attack vectors are likely network‑based, requiring an attacker to deliver a crafted certificate or establish a connection that exploits the validation bypass. Overall risk remains modest, but the flaw remains actionable and should be remediated promptly when updates are available.

Generated by OpenCVE AI on July 31, 2026 at 08:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update that addresses CVE‑2026‑50302 from the MSRC Alert page.
  • Enable strict certificate validation settings in Windows Cryptographic Services, such as revocation checking and name validation, to prevent acceptance of forged certificates.
  • Monitor network connections for unexpected or invalid certificates and enforce stricter validation policies where possible.

Generated by OpenCVE AI on July 31, 2026 at 08:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper certificate validation in Windows Cryptographic Services allows an unauthorized attacker to bypass a security feature over a network.
Title Windows Cryptographic Services Security Feature Bypass Vulnerability
First Time appeared Microsoft
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-295
CPEs cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 21h2 Windows 10 22h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:23:54.744Z

Reserved: 2026-06-04T17:30:16.975Z

Link: CVE-2026-50302

cve-icon Vulnrichment

Updated: 2026-07-15T13:05:26.004Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T08:45:17Z

Weaknesses
  • CWE-295

    Improper Certificate Validation