CVE-2026-72940
massHeap Buffer Overflow in Windows Schannel Allows Remote Code Execution
CVE-2026-72940 is a heap-based buffer overflow (CWE-122) in Microsoft Schannel, the TLS/SSL security package built into Windows. A remote, unauthenticated attacker can trigger the flaw over a network, though the CVSS vector's user-interaction requirement (UI:R) indicates the victim must take some action, such as connecting to an attacker-controlled TLS server or handling attacker-supplied network content. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). Any Windows system using Schannel for TLS is potentially in scope, with the precise affected builds defined in Microsoft's advisory. Exploitation has not been observed: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS puts 30-day exploitation probability at 0.8% (54th percentile).
What to do: Apply Microsoft's security update for the affected Windows builds as soon as it is available, prioritizing endpoints and servers that initiate outbound TLS to untrusted hosts (browsers, mail clients, update agents) and internet-facing services. Because the CVSS vector requires user interaction, reinforce safe-browsing guidance and consider restricting TLS connections to trusted endpoints as an interim mitigation. Verify scope and fixed builds against Microsoft's advisory, since specific affected version numbers are not included in the summary data.
| Microsoft Windows Schannel (TLS/SSL component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Schannel allows an unauthorized attacker to execute code over a network.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.