All findings

CVE-2026-50479 high

Microsoft credits Doyensec collaboration with Claude on USB Hub EoP

Microsoft directly credits Doyensec researchers working with Claude and Anthropic Research for a Windows USB Hub Driver elevation-of-privilege vulnerability.

Bug class
Untrusted pointer dereference and elevation of privilege
Affected codebase
Microsoft Windows USB Hub Driver
Credited system
Claude / Anthropic Research
Disclosed
July 14, 2026
Attribution
Direct source attribution
Severity
high
Source status: Microsoft's Security Update Guide directly credits Adrian Denkiewicz of Doyensec in collaboration with Claude and Anthropic Research and scores the issue CVSS 7.8.

Summary

CVE-2026-50479 is an elevation-of-privilege flaw in the Windows USB Hub Driver, classified under CWE-822 for untrusted pointer dereference. Microsoft assigns CVSS 7.8 and published the fix in the July 2026 security release.

Attribution

This is direct vendor attribution: Microsoft names the human researchers, Claude, and Anthropic Research in the acknowledgment field.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.