CVE Tools

CVE-2026-62757

Windows Schannel Security Feature Bypass Vulnerability

Published: Aug 11, 2026Updated: Aug 16, 2026 Sources: CVE List NVDCWE-347

Description

Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.

In plain language

AI Act now

This is a Windows vulnerability where a remote attacker can send crafted network traffic to make Windows Schannel accept invalid digital signatures, which can damage data integrity; small businesses should patch if these Windows versions are in use, especially on systems exposed to untrusted networks.

Executive summary

An unauthenticated remote attacker can exploit an improper verification in Windows Schannel (CWE-347) to bypass authenticity/signature checks using specially crafted network traffic that causes Windows to accept invalid data, potentially impacting integrity.

If affected, business impact
Data integrity compromiseMan-in-the-middle style effectsService/security disruptionPossible security control bypass

What to do now

  1. Check whether your systems are running any of these: Windows 10, Windows 11, Windows Server 2012/2012 R2, 2016, 2019, 2022, or 2025.
  2. For each affected OS, compare your installed updates/build numbers to the fixed versions listed below (the goal is to be on or above the corresponding fixed build).
  3. Upgrade/apply the Microsoft security update for CVE-2026-62757 using the Microsoft Update Guide for your exact Windows version.
  4. Reboot after installing the update (if required by your patch process) and verify that the OS shows the updated build/version.
  5. Prioritize systems that handle network connections with untrusted clients (web-facing services, VPN endpoints, reverse proxies, edge devices) and those that use Schannel for TLS/cryptography.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:NAC:HPR:NUI:RS:UC:NI:HA:N
Exploitability
AV:NAttack Vector
Network
AC:HAttack Complexity
High
PR:NPrivileges Required
None
UI:RUser Interaction
Required
Scope
S:UScope
Unchanged
Impact
C:NConfidentiality
None
I:HIntegrity
High
A:NAvailability
None

Weaknesses

Affected Products

and 25 more affected products View all →

Exploitability

Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Collection
View detailed technique mapping

References

2

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-62757 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows