CVE-2026-21219: Microsoft Windows Software Development Kit

High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.

Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.

Affected products

  • Microsoft Windows Software Development Kit: from 10.0.26100, before 10.0.26100.7463 (fixed in 10.0.26100.7463)

Published 2026-01-13. Last modified 2026-06-17.