CVE-2026-27912

Published Apr 14, 2026

Last updated 4 months ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-27912 is an improper authorization vulnerability found within Windows Kerberos. This flaw allows an authorized attacker to elevate their privileges when operating over an adjacent network. The vulnerability, classified under CWE-285 (Improper Authorization), stems from the Kerberos authentication protocol's failure to properly validate authorization controls. This enables attackers with initial network access to bypass authorization checks and gain elevated privileges within the affected Windows environment. This vulnerability is also referred to as "ResetNightmare".

Description
Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2022_23h2, windows_server_2025

Risk scores

CVSS 3.1

Type
Primary
Base score
8
Impact score
5.9
Exploitability score
2.1
Vector string
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-285

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

4

Configurations

References

Sources include official advisories and independent security research.