CVE-2026-21517: Microsoft Windows App

High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.

Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally.

Affected products

  • Microsoft Windows App: before 11.3.2 (fixed in 11.3.2)

Published 2026-02-10. Last modified 2026-06-17.