CVE-2026-27912

Published Apr 14, 2026

Last updated 5 months ago

CVSS high 8.0
Windows Kerberos
Windows

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-27912 is an improper authorization vulnerability found within Windows Kerberos. This flaw allows an authorized attacker to elevate their privileges when operating over an adjacent network. The vulnerability, classified under CWE-285 (Improper Authorization), stems from the Kerberos authentication protocol's failure to properly validate authorization controls. This enables attackers with initial network access to bypass authorization checks and gain elevated privileges within the affected Windows environment. This vulnerability is also referred to as "ResetNightmare".

Description
Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2022_23h2, windows_server_2025

Risk scores

CVSS 3.1

Type
Primary
Base score
8
Impact score
5.9
Exploitability score
2.1
Vector string
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-285

Social media

Hype score
Not currently trending
  1. GitHub - Semperis-Community/ResetNightmare: POC tool for ResetNightmare (CVE-2026-27912) · GitHub - https://t.co/HPdubAxzso

    @piedpiper1616

    15 Aug 2026

    402 Impressions

    1 Retweet

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  2. Exploit demo on Linux and Patch Analysis of ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177), two Active Directory vulnerabilities discovered by Shai Laron from @SemperisTech allowing Full Domain Takeover and more. https://t.co/Zx4y9h3ywc

    @rouge_cravate

    10 Aug 2026

    687 Impressions

    4 Retweets

    4 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  3. KerberLoss (CVE-2026-25177) + ResetNightmare (CVE-2026-27912): two Kerberos logic flaws. Low-priv user → any account → domain admin → full domain takeover. Presented today at Black Hat USA by Semperis. https://t.co/QOdioHnQto #infosec #ActiveDirectory

    @Ronin66Official

    9 Aug 2026

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 Windows Kerberos'ta bulunan CVE-2026-27912 numaralı privilege escalation açığı için PoC Exploit yayınlandı. Açık, Windows Server 2012–2025 arası birçok sürümü etkiliyor ve saldırganın ağ üzerinden ayrıcalıklarını yükseltmesine olanak tanıyor. htt

    @ridvanyagli

    9 Aug 2026

    2251 Impressions

    6 Retweets

    37 Likes

    29 Bookmarks

    1 Reply

    0 Quotes

  5. 🚨 PoC released: CVE-2026-27912, a Windows Kerberos privilege escalation vulnerability, now has a public exploit. The flaw affects Windows Server 2012 and allows an authorized attacker to elevate privileges over an adjacent network. PoC: https://t.co/pfaHK1V3JM #Microsoft

    @ThreatWire_

    7 Aug 2026

    1309 Impressions

    2 Retweets

    15 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.