CVE-2026-68846
massUse-after-free privilege escalation in Microsoft Windows Kernel
CVE-2026-68846 is a use-after-free memory-safety flaw (CWE-416) in the Microsoft Windows Kernel, assigned and rated by Microsoft as High severity (CVSS 3.1: 7.1). An authorized attacker with low-privilege access over the network could trigger the bug, which requires user interaction and favorable timing (high attack complexity), causing the kernel to reference freed memory and corrupt its state. Successful exploitation would allow the attacker to elevate privileges on the affected Windows host, with high impact on that system's confidentiality, integrity, and availability. Affected systems are Windows installations with vulnerable kernel builds, though the specific version ranges are not included in the available data. There is currently no public proof-of-concept, no CISA KEV listing, and no known exploitation; EPSS estimates only a 0.6% probability of exploitation within 30 days.
What to do: Install Microsoft's security update for CVE-2026-68846 as soon as it is released, and consult the MSRC advisory for the exact KB/article and affected version list, which were not included in this data. In the interim, restrict authenticated remote access (e.g., RDP and remote management) to trusted users and enforce least privilege, since exploitation requires valid low-privilege credentials and user interaction. Monitor the advisory for new PoCs or KEV additions, which would warrant raising patch priority.
| Microsoft Windows Kernel (Windows operating systems) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.