Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.8

CVE-2026-54109: Windows ReFS Local Code Execution Risk with Authorized Access

CVE-2026-54109 CVE-2026-54109
Summary

The Windows Resilient File System (ReFS) has a security issue that could allow someone with authorized access to run unauthorized code on the system. This is a concern because it could be used to gain control over the system or steal sensitive data. To protect your system, ensure that you keep Windows and ReFS up to date with the latest security patches.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
microsoft windows 10 version 1607 < 10.0.14393.9339
microsoft windows 10 version 1809 < 10.0.17763.9020
microsoft windows 10 version 21h2 < 10.0.19044.7548
microsoft windows 10 version 22h2 < 10.0.19045.7548
microsoft windows 11 version 24h2 < 10.0.26100.8875
microsoft windows 11 version 25h2 < 10.0.26200.8875
microsoft windows 11 version 26h1 < 10.0.28000.2269
microsoft windows server 2016 < 10.0.14393.9339
microsoft windows server 2016 (server core installation) < 10.0.14393.9339
microsoft windows server 2019 < 10.0.17763.9020
microsoft windows server 2019 (server core installation) < 10.0.17763.9020
microsoft windows server 2022 < 10.0.20348.5386
microsoft windows server 2025 < 10.0.26100.33158
microsoft windows server 2025 (server core installation) < 10.0.26100.33158
Original title
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
Original description
Integer overflow or wraparound in Windows Resilient File System (ReFS) allows an authorized attacker to execute code locally.
mitre CVSS3.1 7.8
Vulnerability type
CWE-190 Integer Overflow
CWE-122 Heap-based Buffer Overflow
Published: 14 Jul 2026 · Updated: 20 Jul 2026 · First seen: 14 Jul 2026