Skip to main content

Hitachi
Contact UsContact Us

August 21, 2026
Hitachi, Ltd.

Hitachi Disk Array Systems have the following vulnerability.

Security Information ID

hitachi-sec-2026-315

Vulnerability description

CVE-2026-33828
Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability
CVE-2026-34335
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-40404
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-40409
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-41092
Microsoft Kinect Elevation of Privilege Vulnerability
CVE-2026-41108
Windows DNS Client Elevation of Privilege Vulnerability
CVE-2026-42828
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-42836
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
CVE-2026-42837
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-42903
Windows Kerberos Denial of Service Vulnerability
CVE-2026-42904
Windows TCP/IP Elevation of Privilege Vulnerability
CVE-2026-42905
Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-42906
Windows Shell Information Disclosure Vulnerability
CVE-2026-42907
Windows Shell Information Disclosure Vulnerability
CVE-2026-42908
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-42909
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-42911
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-42912
Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-42914
Windows Kerberos Denial of Service Vulnerability
CVE-2026-42915
Windows TCP/IP Denial of Service Vulnerability
CVE-2026-42916
NT OS Kernel Elevation of Privilege Vulnerability
CVE-2026-42968
Windows Telephony Server Information Disclosure Vulnerability
CVE-2026-42969
Windows Push Notification Information Disclosure Vulnerability
CVE-2026-42970
Windows Push Notification Information Disclosure Vulnerability
CVE-2026-42971
Windows Push Notification Information Disclosure Vulnerability
CVE-2026-42972
Windows Hyper-V Information Disclosure Vulnerability
CVE-2026-42973
Windows Push Notification Information Disclosure Vulnerability
CVE-2026-42977
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-42978
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-42979
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-42980
NT OS Kernel Elevation of Privilege Vulnerability
CVE-2026-42983
Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-42984
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-42985
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-42986
Microsoft Graphics Component Elevation of Privilege Vulnerability
CVE-2026-42989
Winlogon Elevation of Privilege Vulnerability
CVE-2026-42991
Windows Push Notifications Elevation of Privilege Vulnerability
CVE-2026-42992
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-42993
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-44799
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-44801
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-44802
Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-44803
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-44812
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-44815
DHCP Client Service Remote Code Execution Vulnerability
CVE-2026-45487
Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability
CVE-2026-45586
Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability
CVE-2026-45588
Secure Boot Security Feature Bypass Vulnerability
CVE-2026-45592
Windows Internet (wininet.dll) Elevation of Privilege Vulnerability
CVE-2026-45593
Windows SDK Elevation of Privilege Vulnerability
CVE-2026-45594
Windows Application Identity (AppID) Information Disclosure Vulnerability
CVE-2026-45595
Windows Mark of the Web Security Feature Bypass Vulnerability
CVE-2026-45596
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-45598
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-45599
Windows UPnP Device Host Remote Code Execution Vulnerability
CVE-2026-45601
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-45602
Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability
CVE-2026-45603
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-45605
Windows Bluetooth Service Elevation of Privilege Vulnerability
CVE-2026-45606
Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability
CVE-2026-45607
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-45608
Windows DHCP Client Information Disclosure Vulnerability
CVE-2026-45634
Windows DHCP Client Information Disclosure Vulnerability
CVE-2026-45635
Windows UPnP Device Host Remote Code Execution Vulnerability
CVE-2026-45636
Windows NTFS Remote Code Execution Vulnerability
CVE-2026-45637
Microsoft DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-45638
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-45639
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2026-45640
Windows Bluetooth Port Driver Elevation of Privilege Vulnerability
CVE-2026-45641
Windows Hyper-V Remote Code Execution Vulnerability
CVE-2026-45642
Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability
CVE-2026-45653
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-45655
Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-45656
UEFI Secure Boot Security Feature Bypass Vulnerability
CVE-2026-45658
Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-47289
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-47291
HTTP.sys Remote Code Execution Vulnerability
CVE-2026-47648
Windows Storage Elevation of Privilege Vulnerability
CVE-2026-47653
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-47656
Windows Boot Manager Security Feature Bypass Vulnerability
CVE-2026-48563
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2026-48568
Secure Boot Security Feature Bypass Vulnerability
CVE-2026-48570
Secure Boot Security Feature Bypass Vulnerability
CVE-2026-48573
Secure Boot Security Feature Bypass Vulnerability
CVE-2026-48574
Windows Media Remote Code Execution Vulnerability
CVE-2026-48575
Secure Boot Security Feature Bypass Vulnerability
CVE-2026-48576
Secure Boot Security Feature Bypass Vulnerability
CVE-2026-48578
Secure Boot Security Feature Bypass Vulnerability
CVE-2026-48583
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-49160
HTTP.sys Denial of Service Vulnerability
CVE-2026-50507
Windows BitLocker Security Feature Bypass Vulnerability
CVE-2026-8863
UEFI Secure Boot Security Feature Bypass Vulnerability

Affected products

The following table shows the affected products.

Product
Name
Hitachi Virtual Storage Platform 5200, 5600, 5200H, 5600H
Hitachi Virtual Storage Platform 5100, 5500, 5100H, 5500H
Vulnerability
ID

[Windows 10 for x64-based Systems (Version1809)]

CVE-2026-33828, CVE-2026-34335, CVE-2026-40404, CVE-2026-40409,
CVE-2026-41092, CVE-2026-41108, CVE-2026-42828, CVE-2026-42836,
CVE-2026-42837, CVE-2026-42903, CVE-2026-42905, CVE-2026-42907,
CVE-2026-42908, CVE-2026-42909, CVE-2026-42911, CVE-2026-42912,
CVE-2026-42914, CVE-2026-42916, CVE-2026-42968, CVE-2026-42969,
CVE-2026-42970, CVE-2026-42971, CVE-2026-42972, CVE-2026-42973,
CVE-2026-42977, CVE-2026-42978, CVE-2026-42979, CVE-2026-42980,
CVE-2026-42983, CVE-2026-42984, CVE-2026-42985, CVE-2026-42986,
CVE-2026-42989, CVE-2026-42991, CVE-2026-42992, CVE-2026-44799,
CVE-2026-44801, CVE-2026-44802, CVE-2026-44803, CVE-2026-44812,
CVE-2026-44815, CVE-2026-45586, CVE-2026-45588, CVE-2026-45592,
CVE-2026-45593, CVE-2026-45594, CVE-2026-45595, CVE-2026-45596,
CVE-2026-45598, CVE-2026-45599, CVE-2026-45601, CVE-2026-45602,
CVE-2026-45603, CVE-2026-45605, CVE-2026-45606, CVE-2026-45607,
CVE-2026-45608, CVE-2026-45634, CVE-2026-45635, CVE-2026-45636,
CVE-2026-45637, CVE-2026-45638, CVE-2026-45639, CVE-2026-45642,
CVE-2026-45653, CVE-2026-45655, CVE-2026-45656, CVE-2026-45658,
CVE-2026-47289, CVE-2026-47291, CVE-2026-47648, CVE-2026-47653,
CVE-2026-47656, CVE-2026-48563, CVE-2026-48568, CVE-2026-48570,
CVE-2026-48573, CVE-2026-48574, CVE-2026-48575, CVE-2026-48576,
CVE-2026-48578, CVE-2026-48583, CVE-2026-49160, CVE-2026-50507,
CVE-2026-8863

[Windows 10 for x64-based Systems (Version21H2)]

CVE-2026-33828, CVE-2026-34335, CVE-2026-40404, CVE-2026-40409,
CVE-2026-41092, CVE-2026-41108, CVE-2026-42828, CVE-2026-42836,
CVE-2026-42837, CVE-2026-42903, CVE-2026-42904, CVE-2026-42905,
CVE-2026-42906, CVE-2026-42907, CVE-2026-42908, CVE-2026-42909,
CVE-2026-42911, CVE-2026-42912, CVE-2026-42914, CVE-2026-42915,
CVE-2026-42916, CVE-2026-42968, CVE-2026-42969, CVE-2026-42970,
CVE-2026-42971, CVE-2026-42972, CVE-2026-42973, CVE-2026-42977,
CVE-2026-42978, CVE-2026-42979, CVE-2026-42980, CVE-2026-42983,
CVE-2026-42984, CVE-2026-42985, CVE-2026-42986, CVE-2026-42989,
CVE-2026-42991, CVE-2026-42992, CVE-2026-42993, CVE-2026-44799,
CVE-2026-44801, CVE-2026-44802, CVE-2026-44803, CVE-2026-44812,
CVE-2026-44815, CVE-2026-45487, CVE-2026-45586, CVE-2026-45588,
CVE-2026-45592, CVE-2026-45593, CVE-2026-45594, CVE-2026-45595,
CVE-2026-45596, CVE-2026-45598, CVE-2026-45599, CVE-2026-45601,
CVE-2026-45602, CVE-2026-45603, CVE-2026-45605, CVE-2026-45606,
CVE-2026-45607, CVE-2026-45608, CVE-2026-45634, CVE-2026-45635,
CVE-2026-45636, CVE-2026-45637, CVE-2026-45638, CVE-2026-45639,
CVE-2026-45640, CVE-2026-45641, CVE-2026-45642, CVE-2026-45653,
CVE-2026-45655, CVE-2026-45656, CVE-2026-45658, CVE-2026-47289,
CVE-2026-47291, CVE-2026-47648, CVE-2026-47653, CVE-2026-47656,
CVE-2026-48563, CVE-2026-48568, CVE-2026-48570, CVE-2026-48573,
CVE-2026-48574, CVE-2026-48575, CVE-2026-48576, CVE-2026-48578,
CVE-2026-48583, CVE-2026-49160, CVE-2026-50507, CVE-2026-8863

The following products are not affected by the vulnerabilities:

  • Hitachi Virtual Storage Platform E590, E790, E990, E1090, E590H, E790H, E1090H
  • Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900
  • Hitachi Virtual Storage Platform F350, F370, F700, F900
  • Hitachi Virtual Storage Platform G100, G200, G400, G600, G800
  • Hitachi Virtual Storage Platform F400, F600, F800
  • Hitachi Virtual Storage Platform N400, N600, N800

Action to be taken

Software update.
Please contact your authorized service representative for details on any corrective actions such as software updates and the schedule for their release.

References

Please refer to the Security Update Guide (Microsoft) about the vulnerabilities.

Revision history

  • August 21, 2026: This security information page is published.
  • Hitachi, Ltd. (hereinafter referred to as "Hitachi") tries to provide accurate information about security countermeasures. However, since information about security problems constantly changes, the contents of these Web pages are subject to change without prior notice. When referencing information, please confirm that you are referencing the latest information.
  • The Web pages include information about products that are developed by non-Hitachi software developers. Vulnerability information about those products is based on the information provided or disclosed by those developers. Although Hitachi is careful about the accuracy and completeness of this information, the contents of the Web pages may change depending on the changes made by the developers.
  • The Web pages are intended to provide vulnerability information only, and Hitachi shall not have any legal responsibility for the information contained in them. Hitachi shall not be liable for any consequences arising out of or in connection with the security countermeasures or other actions that you will take or have taken (or not taken) by yourself.
  • The links to other web sites are valid at the time of the release of the page. Although Hitachi makes an effort to maintain the links, Hitachi cannot guarantee their permanent availability.