CVE-2026-50657Important
Microsoft Defender for Endpoint for Mac Information Disclosure Vulnerability
Assessment
Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally.
- Severity
- Important
- CVSS base score
- 4.7CVSS:3.1/
AV:L/ AC:H/ PR:L/ UI:N/ S:U/ C:H/ I:N/ A:N/ E:U/ RL:O/ RC:C - Impact
- Information Disclosure
- EPSS, next 30 days
- 0.4%Higher than 31.6% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Exploitation Less Likely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Microsoft Defender
- Weakness
- CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
- Issued by
- Microsoft
- Published
- 14 Jul 2026 · July 2026
- Last revised
- 14 Jul 2026
Updates that fix it
0 KBsNo KB listed
MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.
Affected products
System Center1 affected product
- Microsoft Defender for Endpoint for Mac