AI analysis
CVE-2026-83979 is a use-after-free flaw (CWE-416) in the Windows Biometric Service, the component that handles fingerprint, facial, and other biometric authentication on Windows. An attacker who is already authorized on the machine with low privileges can trigger the bug, presumably by sending crafted input to the service that causes memory to be used after it has been freed. Successful exploitation allows local elevation of privileges, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8, AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The affected range spans mainstream Windows 10 and Windows 11 client releases plus Windows Server 2016 through 2025, covering nearly the entire currently supported Windows estate. As of the September 2026 Patch Tuesday disclosure there is no CISA KEV listing, no known public proof-of-concept, and EPSS estimates only a 0.3% chance of exploitation within 30 days; the flaw is not identified as one of the two zero-days actively exploited that month.
What to do: Apply Microsoft's September 2026 security updates to all affected Windows 10/11 clients and Windows Server hosts, prioritizing multi-user endpoints, shared workstations, and remote machines where untrusted users hold local sign-in rights. Because exploitation requires a local low-privileged foothold, review and restrict which accounts can log on interactively to servers in the meantime. Where Windows Hello or biometric sign-in is not used, disabling the Windows Biometric Service is a reasonable interim risk reduction pending patching.
Affected
| Microsoft Windows 10 | 1607 (builds prior to the September 2026 security updates) |
| Microsoft Windows 10 | 1809 (builds prior to the September 2026 security updates) |
| Microsoft Windows 10 | 21H2 (builds prior to the September 2026 security updates) |
| Microsoft Windows 10 | 22H2 (builds prior to the September 2026 security updates) |
| Microsoft Windows 11 | 23H2 (builds prior to the September 2026 security updates) |
| Microsoft Windows 11 | 24H2 (builds prior to the September 2026 security updates) |
| Microsoft Windows 11 | 25H2 (builds prior to the September 2026 security updates) |
| Microsoft Windows 11 | 26H1 (builds prior to the September 2026 security updates) |
| Microsoft Windows Server 2016 | all supported builds prior to the September 2026 security updates |
| Microsoft Windows Server 2019 | all supported builds prior to the September 2026 security updates |
| Microsoft Windows Server 2022 | all supported builds prior to the September 2026 security updates |
| Microsoft Windows Server 2025 | all supported builds prior to the September 2026 security updates |
Estimated exposure
mass≈ hundreds of millions of Windows devices (affected versions cover the mainstream Windows 10/11 client and Windows Server install base) — The listed versions span essentially the entire supported Windows ecosystem, which public market-share data places at well over a billion Windows devices, and the Windows Biometric Service is present by default on these releases; practical…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.