CVE-2026-33694: exploitation status and patch state
CVE-2026-33694
This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially facilitates arbitrary code execution, whereby an attacker may exploit the vulnerability to execute malicious code with elevated SYSTEM privileges.
Is CVE-2026-33694 exploited?
Not in the CISA KEV catalog.
Public exploit code: none found in monitored sources.