PT-2026-24331 · Microsoft · Windows

·

CVE-2026-26128

·

Published

2026-03-10

·

Updated

2026-07-12

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows 10 Version 1607 Windows Server 2025 Windows Server 2011
Description Improper authentication in the Windows SMB Server allows an authorized attacker to elevate privileges locally. The issue involves a Kerberos reflection bypass, which can enable an attacker to gain SYSTEM privileges on most Windows builds. Approximately 756,600 instances were identified globally.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02973
CVE-2026-26128

Affected Products

Windows