Microsoft patched CVE-2026-50458, a high-severity local privilege escalation flaw in the Windows Brokering File System driver, bfs.sys, that affects Windows 11 and Windows Server 2025. The vulnerability stems from a race condition that can trigger a use-after-free in BFS internal directory handling, allowing a locally authenticated attacker or sandboxed code to corrupt kernel memory and elevate privileges to SYSTEM.
Affected platforms include Windows 11 24H2, 25H2, and 26H1 on x64 and ARM64, along with Windows Server 2025 including Server Core, prior to patched builds. Microsoft assigned the issue a CVSS 7.8 rating and addressed it in July 2026 security updates, including KB5101650 for Windows 11 24H2 and 25H2. Public discussion around the bug includes a technical deep dive into the kernel minifilter vulnerability, but there are no confirmed reports of active exploitation, and the flaw is not listed in CISA’s Known Exploited Vulnerabilities catalog.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A technical deep dive described CVE-2026-50458 as a use-after-free vulnerability in the Windows Brokering File System minifilter driver, bfs.sys. Reporting says the flaw stems from a race condition in BFS internal directory handling that can let a locally authenticated attacker or sandboxed code corrupt kernel memory and escalate privileges to SYSTEM.
Microsoft fixed CVE-2026-50458, a high-severity local privilege escalation flaw in the Windows Brokering File System driver bfs.sys, in its July 2026 security updates. The issue affects Windows 11 and Windows Server 2025 before the patched builds, and one cited fix is KB5101650 for Windows 11 24H2 and 25H2.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcereddit.com
Open sourcerotcee.github.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.