cbcvebase.
CVE-2026-21530
published 2026-05-12

CVE-2026-21530: Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

PriorityP432medium6.7CVSS 3.1
AVLACHPRLUIRSUCHIHAH
EPSS
0.32%
24.2th percentile
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftmicrosoft_365_apps_for_enterprise>= 16.0.1 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_2016>= 16.0.0 < 16.0.5556.100016.0.5556.1000
microsoftmicrosoft_office_2019>= 19.0.0 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_ltsc_2021>= 16.0.1 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftmicrosoft_office_ltsc_2024>= 16.0.0 < https://aka.ms/OfficeSecurityReleaseshttps://aka.ms/OfficeSecurityReleases
microsoftwindows_10_1607< 10.0.14393.914010.0.14393.9140
microsoftwindows_10_1809< 10.0.17763.875510.0.17763.8755
microsoftwindows_10_21h2< 10.0.19044.729110.0.19044.7291
microsoftwindows_10_22h2< 10.0.19045.729110.0.19045.7291
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.914010.0.14393.9140
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.875510.0.17763.8755
microsoftwindows_10_version_21h2>= 10.0.19044.0 < 10.0.19044.729110.0.19044.7291
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.741710.0.19045.7417
microsoftwindows_11_23h2< 10.0.22631.707910.0.22631.7079
microsoftwindows_11_24h2< 10.0.26100.839010.0.26100.8390
microsoftwindows_11_25h2< 10.0.26200.845710.0.26200.8457
microsoftwindows_11_26h1< 10.0.28000.211310.0.28000.2113
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.707910.0.22631.7079
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.721910.0.22631.7219
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.845710.0.26100.8457
microsoftwindows_11_version_25h2>= 10.0.26200.0 < 10.0.26200.845710.0.26200.8457
microsoftwindows_11_version_26h1>= 10.0.28000.0 < 10.0.28000.211310.0.28000.2113
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.260796.2.9200.26079
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.231816.3.9600.23181
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.