CVE-2026-27912
HIGH 8.0EPSS 0.4%
Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.
- CVSS v3.1
- 8.0 HIGH
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 0.41% chance of exploitation in the next 30 days, 34th percentile
- Published
- 2026-04-14
- Updated
- 2026-08-14
Proof-of-concept exploits (5)
- Semperis-Community/ResetNightmare209★ · 2026-08-20
- mihat2/ResetNightmare-impacket4★ · 2026-08-11
- oxstussz-eng/Kerberos-CVE-2026-279122★ · 2026-08-14
- XedSama/ResetNightmare-Python12★ · 2026-08-06
- kdRajKit/ResetNightmare-C-code-POC1★ · 2026-08-21