CVE-2026-21517: Microsoft Windows App
High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally.
Affected products
- Microsoft Windows App: before 11.3.2 (fixed in 11.3.2)
Published 2026-02-10. Last modified 2026-06-17.