All findings

CVE-2026-62746 medium

Microsoft directly credits Xint on Win32k information disclosure

MSRC directly credits Theori working with Xint on CVE-2026-62746, a Win32k information-disclosure vulnerability.

Bug class
Information disclosure
Affected codebase
Microsoft Win32k
Credited system
Xint Code
Disclosed
August 11, 2026
Attribution
Direct source attribution
Severity
medium
Source status: MSRC directly acknowledges Theori with Xint on CVE-2026-62746 and assigns CVSS 5.5.

Summary

The accepted Microsoft record extends Xint’s direct vendor-credit trail into Win32k. The CNA score is medium, and Bugflation preserves that rating rather than raising it based on the broader system profile.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.