CVE-2026-27912
Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
- Affected products
- Windows, Windows Kerberos
- Microsoft Windows Server 2012
- All versions
- Microsoft Windows Server 2016
- < 10.0.14393.9060
- Microsoft Windows Server 2019
- < 10.0.17763.8644
- Microsoft Windows Server 2022
- < 10.0.20348.5020
- Microsoft Windows Server 2022 23h2
- < 10.0.25398.2274
- Microsoft Windows Server 2025
- < 10.0.26100.32690
- CVSS 3.1
- 8.0 HIGH
- EPSS
- 0.2% (15th percentile)
- Weakness
- CWE-285
- NVD status
- Analyzed
- Published
- 2026-04-14
CVE-2026-27912 at NVD
1 known exploit for CVE-2026-27912
Proof-of-concept code and exploit modules indexed by Sploitus