Source status: Microsoft's Security Update Guide explicitly says Frederica of Tencent Xuanwu Lab used the Atuin Automated Vulnerability Discovery System; the advisory also lists other reporters.
Summary
CVE-2026-26168 affects the Windows Ancillary Function Driver for Winsock and can allow elevation of privilege. It is a historical omission from the April 2026 release rather than a new July disclosure.
Attribution
Microsoft directly names Atuin and makes clear that other researchers also reported the vulnerability. Bugflation records participation, not exclusivity.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.