CVE-2026-72971: exploitation status and patch state
CVE-2026-72971 · CVSS 5.5 MEDIUM · patch available
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
Is CVE-2026-72971 exploited?
Not in the CISA KEV catalog.
Public exploit code: none found in monitored sources.
Which products and versions are affected?
Microsoft · Windows 11 Version 26H1 for ARM64-based Systems · < 10.0.28000.2704
Microsoft · Windows 11 version 26H1 for x64-based Systems · < 10.0.28000.2704