Description
Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.
Published: 2026-07-14
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Access of a resource using an incompatible type, known as type confusion, occurs within the Windows Object Linking and Embedding (OLE) subsystem. This flaw allows an attacker who can supply malicious OLE data over a network to execute arbitrary code with the privileges of the local user or system service that processes the request. The impact includes full control over the affected machine as the attacker can run any code that the account can run. This vulnerability is classified as a critical Remote Code Execution flaw reflected by its CVSS score of 8.1.

Affected Systems

Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 24H2, 25H2, 26H1; Windows Server 2012 R2, 2016, 2019, 2022, 2025. The affected builds run on x86, x64 and arm64 architectures where applicable. All these operating systems contain the vulnerable OLE component that must be patched.

Risk and Exploitability

The CVSS score indicates a high severity defect, yet the EPSS score of less than 1 percent shows a very low likelihood of exploitation in the wild at present. Nonetheless, the flaw is not listed in the CISA Known Exploited Vulnerabilities catalog, meaning no publicly available exploit has been observed, but the possibility remains. Attackers would likely need to craft a malicious OLE object and deliver it over the network to a target that processes OLE data, making the typical attack vector an authenticated or unauthenticated network or local interaction with the OLE service. Because remote code execution can lead to privilege escalation and complete system compromise, the risk to both client and server deployments remains high.

Generated by OpenCVE AI on July 31, 2026 at 07:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the Microsoft security update that addresses CVE-2026-50686 from the official Microsoft Update Catalog or Windows Update.
  • After applying the patch, restrict or disable unnecessary OLE server functionality and control network paths that deliver OLE content to mitigate the attack surface.
  • Review OLE usage in your environment, isolate affected systems in a secured subnet, and monitor for anomalous OLE traffic or unauthorized code execution attempts.

Generated by OpenCVE AI on July 31, 2026 at 07:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.
Title Windows OLE Remote Code Execution Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
Weaknesses CWE-843
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2012_R2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2012 R2
Microsoft windows Server 2016
Microsoft windows Server 2019
Microsoft windows Server 2022
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2012 R2 Windows Server 2016 Windows Server 2019 Windows Server 2022 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:25:54.172Z

Reserved: 2026-06-05T14:35:07.080Z

Link: CVE-2026-50686

cve-icon Vulnrichment

Updated: 2026-07-15T13:06:40.539Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:15:03Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')