5.3

CVE-2026-65777

Medienbericht

Active Directory Security Feature Bypass Vulnerability

Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MicrosoftWindows 11 23h2 HwPlatformarm64 Version < 10.0.22631.7517
MicrosoftWindows 11 23h2 HwPlatformx64 Version < 10.0.22631.7517
MicrosoftWindows 11 24h2 HwPlatformarm64 Version < 10.0.26100.9106
MicrosoftWindows 11 24h2 HwPlatformx64 Version < 10.0.26100.9106
MicrosoftWindows 11 25h2 HwPlatformarm64 Version <= 10.0.26200.9106
MicrosoftWindows 11 25h2 HwPlatformx64 Version < 10.0.26200.9106
MicrosoftWindows 11 26h1 HwPlatformarm64 Version < 10.0.28000.2704
MicrosoftWindows 11 26h1 HwPlatformx64 Version < 10.0.28000.2704
MicrosoftWindows Server 2022 Version < 10.0.20348.5440
MicrosoftWindows Server 2025 Version < 10.0.26100.33222
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.29% 0.213
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Microsoft 5.3 1.6 3.6
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
CWE-326 Inadequate Encryption Strength

The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
11.08.2026 20:25
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65777
Patch
Vendor Advisory