AI analysis
CVE-2026-83976 is a heap-based buffer overflow (CWE-122) in the Windows Biometric Service affecting Windows 10, Windows 11, and Windows Server. A local, authenticated (low-privileged) user can trigger the overflow by sending crafted input to the service, corrupting heap memory and executing code in the service's security context. Successful exploitation allows the attacker to elevate privileges on the local machine, with high impact on confidentiality, integrity, and availability per the CVSS 7.8 score; no user interaction or remote access is required beyond an existing local session. All listed Windows client builds (Windows 10 1607 through Windows 11 26H1) and Windows Server 2016 through 2025 are affected, with the greatest practical exposure on machines equipped with Windows Hello fingerprint or face authentication hardware. No public proof of concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a 0.2% probability of exploitation within 30 days; Microsoft's September 2026 Patch Tuesday fixed 973 vulnerabilities including two exploited zero-days, but this flaw is not confirmed to be among them.
What to do: Apply Microsoft's September 2026 security updates on all affected Windows 10, Windows 11, and Windows Server builds via Windows Update, WSUS, or your patch management platform, prioritizing shared or multi-user machines (kiosks, shared workstations) and devices with Windows Hello sensors. Inventory endpoints for the listed builds and confirm the patch is installed; no public PoC or workaround is known, so patching is the primary remediation.
Affected
| microsoft Windows 10 | 1607, 1809, 21H2, 22H2 |
| microsoft Windows 11 | 23H2, 24H2, 25H2, 26H1 |
| microsoft Windows Server | 2016, 2019, 2022, 2025 |
Estimated exposure
masshundreds of millions of Windows client and server installations (Biometric Service ships by default on all listed versions) — Windows 10 and 11 run on well over a billion active devices and the Windows Biometric Service is present by default on every listed client and server version, with practical exploitability concentrated on systems with Windows Hello…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.