We use optional cookies to improve your experience on our websites, such as through social media connections, and to display personalized advertising based on your online activity. If you reject optional cookies, only cookies necessary to provide you the services will be used. You may change your selection by clicking โManage Cookiesโ at the bottom of the page. Privacy Statement Third-Party Cookies AcceptRejectManage cookies MSRC ๎ฌ Customer Guidance ๎ฌ Security Update Guide ๎ฌ Vulnerabilities ๎ฌ CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability New On this page ๎ CVE-2026-40400 ๎ Subscribe RSS PowerShell ๎ฅ API ๎ฅ CSAF Security Vulnerability Released: Jul 14, 2026 Assigning CNA Microsoft CVE.org link CVE-2026-40400 ๏ Impact Remote Code Execution Max Severity Important Weakness CWE-23: Relative Path Traversal CVSS Source Microsoft Vector String CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C Metrics CVSS:3.1 8.0 / 7.0 ๎ฅ Base score metrics: 8.0 / Temporal score metrics: 7.0 ๎ฅฎ Expand all ๎ฅฐ Collapse all Metric Value ๎ฃฌ ๎ฅด Base score metrics(8) Attack Vector Network Attack Complexity Low Privileges Required Low User Interaction Required Scope Unchanged Confidentiality High Integrity High Availability High ๎ฃฌ ๎ฅด Temporal score metrics(3) Exploit Code Maturity Unproven Remediation Level Official Fix Report Confidence Confirmed Please see Common Vulnerability Scoring System for more information on the definition of these metrics. Executive Summary Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. Exploitability The following table provides an exploitability assessment for this vulnerability at the time of original publication. Publicly disclosed No Exploited No Exploitability assessment Exploitation Unlikely FAQ According to the CVSS metric, the attack vector is network (AV:N) and the user interaction is required (UI:R). What is the target context of the remote code execution? This attack requires an authenticated client to click a link so that an unauthenticated attacker can initiate remote code execution. Acknowledgements TrendAI Zero Day Initiative ๏ Anonymous ๏ Daniel R Povcfe Ky0toFu Jishnu Sudhakaran YMsora https://www.ymsora.com/ PuH4ck3rX https://puh4ck3rx.github.io/ with W&M PuH4ck3rX MinhNV5 with MBBank https://mbbank.com.vn/ Michael Monwuba with Microsoft ๏ Charlie Vogt Rayhan Destian https://rayhan.ch/ Rayhan Destian Anindya Roy ๐ @ theteatoast Peng Zhou (zpbrent) https://zpbrent.github.io/ Saif Shaker Quan Le from Unit 515 - OPSWAT Microsoft recognizes the efforts of those in the security community who help us protect customers through coordinated vulnerability disclosure. See Acknowledgements for more information. Security Updates To determine the support lifecycle for your software, see the Microsoft Support Lifecycle. Release date Descending ๎ Edit columns ๎ข Download ๎ Filters ๎ก Product Family ๎ Max Severity ๎ Impact ๎ Platform ๎ ๎ข Clear Release date ๎นฉ Product Platform Impact Max Severity Article Download Build Number Assigning CNA Title: Release date, Content: Jul 14, 2026 Windows 10 Version 22H2 for ARM64-based Systems - Remote Code Execution Important Title: Knowledge Base Articles for Windows 10 Version 22H2 for ARM64-based Systems, Content:, 1 link 5099539 ๏ Title: Download Security Update for Windows 10 Version 22H2 for ARM64-based Systems, Content:, 1 link Security Update ๏ Title: Build numbers, Content: 10.0.19045.7548 Title: Assigning CNA, Content: Microsoft Title: Release date, Content: Jul 14, 2026 Windows 10 Version 22H2 for x64-based Systems - Remote Code Execution Important Title: Knowledge Base Articles for Windows 10 Version 22H2 for x64-based Systems, Content:, 1 link 5099539 ๏ Title: Download Security Update for Windows 10 Version 22H2 for x64-based Systems, Content:, 1 link Security Update ๏ Title: Build numbers, Content: 10.0.19045.7548 Title: Assigning CNA, Content: Microsoft Title: Release date, Content: Jul 14, 2026 Windows 10 Version 21H2 for x64-based Systems - Remote Code Execution Important Title: Knowledge Base Articles for Windows 10 Version 21H2 for x64-based Systems, Content:, 1 link 5099539 ๏ Title: Download Security Update for Windows 10 Version 21H2 for x64-based Systems, Content:, 1 link Security Update ๏ Title: Build numbers, Content: 10.0.19044.7548 Title: Assigning CNA, Content: Microsoft Title: Release date, Content: Jul 14, 2026 Windows 10 Version 21H2 for ARM64-based Systems - Remote Code Execution Important Title: Knowledge Base Articles for Windows 10 Version 21H2 for ARM64-based Systems, Content:, 1 link 5099539 ๏ Title: Download Security Update for Windows 10 Version 21H2 for ARM64-based Systems, Content:, 1 link Security Update ๏ Title: Build numbers, Content: 10.0.19044.7548 Title: Assigning CNA, Content: Microsoft Title: Release date, Content: Jul 14, 2026 Windows 10 Version 21H2 for 32-bit Systems - Remote Code Execution Important Title: Knowledge Base Articles for Windows 10 Version 21H2 for 32-bit Systems, Content:, 1 link 5099539 ๏ Title: Download Security Update for Windows 10 Version 21H2 for 32-bit Systems, Content:, 1 link Security Update ๏ Title: Build numbers, Content: 10.0.19044.7548 Title: Assigning CNA, Content: Microsoft Title: Release date, Content: Jul 14, 2026 Windows Server 2022 - Remote Code Execution Important Title: Knowledge Base Articles for Windows Server 2022, Content:, 1 link 5099540 ๏ Title: Download Security Update for Windows Server 2022, Content:, 1 link Security Update ๏ Title: Build numbers, Content: 10.0.20348.5386 Title: Assigning CNA, Content: Microsoft Title: Release date, Content: Jul 14, 2026 Windows Server 2019 (Server Core installation) - Remote Code Execution Important Title: Knowledge Base Articles for Windows Server 2019 (Server Core installation), Content:, 1 link 5099538 ๏ Title: Download Security Update for Windows Server 2019 (Server Core installation), Content:, 1 link Security Update ๏ Title: Build numbers, Content: 10.0.17763.9020 Title: Assigning CNA, Content: Microsoft Title: Release date, Content: Jul 14, 2026 Windows Server 2019 - Remote Code Execution Important Title: Knowledge Base Articles for Windows Server 2019, Content:, 1 link 5099538 ๏ Title: Download Security Update for Windows Server 2019, Content:, 1 link Security Update ๏ Title: Build numbers, Content: 10.0.17763.9020 Title: Assigning CNA, Content: Microsoft Title: Release date, Content: Jul 14, 2026 Windows 10 Version 1809 for x64-based Systems - Remote Code Execution Important Title: Knowledge Base Articles for Windows 10 Version 1809 for x64-based Systems, Content:, 1 link 5099538 ๏ Title: Download Security Update for Windows 10 Version 1809 for x64-based Systems, Content:, 1 link Security Update ๏ Title: Build numbers, Content: 10.0.17763.9020 Title: Assigning CNA, Content: Microsoft Title: Release date, Content: Jul 14, 2026 Windows 10 Version 1809 for 32-bit Systems - Remote Code Execution Important Title: Knowledge Base Articles for Windows 10 Version 1809 for 32-bit Systems, Content:, 1 link 5099538 ๏ Title: Download Security Update for Windows 10 Version 1809 for 32-bit Systems, Content:, 1 link Security Update ๏ Title: Build numbers, Content: 10.0.17763.9020 Title: Assigning CNA, Content: Microsoft Title: Release date, Content: Jul 14, 2026 Windows Server 2025 (Server Core installation) - Remote Code Execution Important Title: Knowledge Base Articles for Windows Server 2025 (Server Core installation), Content:, 1 link 5099536 ๏ Title: Download Security Update for Windows Server 2025 (Server Core installation), Content:, 1 link Security Update ๏ Title: Build numbers, Content: 10.0.26100.33158 Title: Assigning CNA, Content: Microsoft Title: Release date, Content: Jul 14, 2026 Windows 10 Version 22H2 for 32-bit Systems - Remote Code Execution Important Title: Knowledge Base Articles for Windows 10 Version 22H2 for 32-bit Systems, Content:, 1 link 5099539 ๏ Title: Download Security Update for Windows 10 Version 22H2 for 32-bit Systems, Content:, 1 link Security Update ๏ Title: Build numbers, Content: 10.0.19045.7548 Title: Assigning CNA, Content: Microsoft Title: Release date, Content: Jul 14, 2026 Windows Server 2012 R2 (Server Core installation) - Remote Code Execution Important Title: Knowledge Base Articles for Windows Server 2012 R2 (Server Core installation), Content:, 1 link 5099444 ๏ Title: Download Security Update for Windows Server 2012 R2 (Server Core installation), Content:, 1 link Monthly Rollup ๏ Title: Build numbers, Content: 6.3.9600.23291 Title: Assigning CNA, Content: Microsoft Title: Release date, Content: Jul 14, 2026 Windows Server 2012 R2 - Remote Code Execution Important Title: Knowledge Base Articles for Windows Server 2012 R2, Content:, 1 link 5099444 ๏ Title: Download Security Update for Windows Server 2012 R2, Content:, 1 link Monthly Rollup ๏ Title: Build numbers, Content: 6.3.9600.23291 Title: Assigning CNA, Content: Microsoft Title: Release date, Content: Jul 14, 2026 Windows Server 2012 (Server Core installation) - Remote Code Execution Important Title: Knowledge Base Articles for Windows Server 2012 (Server Core installation), Content:, 1 link 5099445 ๏ Title: Download Security Update for Windows Server 2012 (Server Core installation), Content:, 1 link Monthly Rollup ๏ Title: Build numbers, Content: 6.2.9200.26226 Title: Assigning CNA, Content: Microsoft Title: Release date, Content: Jul 14, 2026 Windows Server 2012 - Remote Code Execution Important Title: Knowledge Base Articles for Windows Server 2012, Content:, 1 link 5099445 ๏ Title: Download Security Update for Windows Server 2012, Content:, 1 link Monthly Rollup ๏ Title: Build numbers, Content: 6.2.9200.26226 Title: Assigning CNA, Content: Microsoft Title: Release date, Content: Jul 14, 2026 Windows Server 2016 (Server Core installation) - Remote Code Execution Important Title: Knowledge Base Articles for Windows Server 2016 (Server Core installation), Content:, 1 lin
A critical remote code execution vulnerability (CVE-2026-40400, CVSS 8.0 HIGH) exists in Windows PowerShell due to a relative path traversal weakness (CWE-23). The attack vector is network-based and requires an authenticated user to click a link, which then allows an unauthenticated attacker to execute arbitrary code. Microsoft has released an official fix; administrators should apply the security updates referenced in the Microsoft Security Update Guide immediately.