CVE-2026-77493
massDouble-free RCE in Microsoft Graphics Component affects Windows and Windows Server
CVE-2026-77493 is a double-free memory corruption flaw (CWE-415) in the Microsoft Graphics Component, rated critical at CVSS 9.8. Per the CVSS vector (AV:N/AC:L/PR:N/UI:N), an unauthenticated attacker can reach the vulnerable code over the network with no user interaction, delivering crafted input that causes the component to free the same memory allocation twice, corrupting the heap. Successful exploitation results in arbitrary code execution with high impact on confidentiality, integrity, and availability. The affected CPE list spans Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server 2012, 2016, 2019, and 2022, effectively covering the currently supported Windows client and server releases named in the data. No public proof-of-concept or in-the-wild exploitation is known, the flaw is not in CISA's KEV catalog, and EPSS estimates roughly a 1% probability of exploitation within the next 30 days (60th percentile).
What to do: Apply Microsoft's security update for CVE-2026-77493 through Windows Update or your patch-management channel as soon as it is published, prioritizing internet-facing Windows Servers (2012/2016/2019/2022) and remote-access endpoints because the flaw is network-exploitable without authentication or user interaction. Inventory Windows builds against the affected version list to confirm scope, and watch for KEV listing or public PoC releases as triggers to expedite emergency patching. No workarounds are documented in the available data.
| microsoft Windows 10 | 1607 |
| microsoft Windows 10 | 1809 |
| microsoft Windows 10 | 21H2 |
| microsoft Windows 10 | 22H2 |
| microsoft Windows 11 | 23H2 |
| microsoft Windows 11 | 24H2 |
| microsoft Windows 11 | 25H2 |
| microsoft Windows 11 | 26H1 |
| microsoft Windows Server 2012 | 2012 |
| microsoft Windows Server 2016 | 2016 |
| microsoft Windows Server 2019 | 2019 |
| microsoft Windows Server 2022 | 2022 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-415
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.