CVE-2026-69366
massUse-after-free privilege escalation in Microsoft Windows Kernel
CVE-2026-69366 is a use-after-free (CWE-416) in the Microsoft Windows Kernel that allows an authorized attacker to elevate privileges over a network. A low-privileged attacker can trigger the flaw through network-reachable conditions that require user interaction, causing the kernel to reference memory after it has been freed. Successful exploitation yields elevation of privilege, with the CVSS vector indicating high impact to confidentiality, integrity, and availability within the victim's security scope. All Windows systems running the kernel versions affected per Microsoft's advisory are exposed; the provided data does not enumerate specific affected builds. There is no confirmed exploitation in the wild: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a 0.6% chance of exploitation within 30 days.
What to do: Apply Microsoft's current Windows security (cumulative) update addressing CVE-2026-69366 as soon as it is available, prioritizing multi-user systems, remote desktop/session hosts, and internet-exposed servers, and verify installed builds against the affected ranges in Microsoft's advisory. Until patching is complete, limit low-privileged remote access and instruct users to be cautious with interactive prompts on exposed systems. Monitor Microsoft's advisory and the dashboard for updates, as exploitation likelihood (EPSS 0.6%) could change once exploit details or PoCs appear.
| Microsoft Windows Kernel (Windows operating systems) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Kernel allows an authorized attacker to elevate privileges over a network.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.