CVE-2026-68880
Windows Win32k Elevation of Privilege Vulnerability
Description
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges over a network.
In plain language
AI Act nowCVE-2026-68880 is a serious Windows security bug that can let an attacker gain higher privileges, and most small businesses should treat it as urgent to patch—especially if any Windows machines are exposed to untrusted networks or users can be tricked. The exact fixed Windows builds are listed below.
CVE-2026-68880 is a Windows Win32k heap-based buffer overflow (CWE-122 / CWE-197) that can be triggered via Windows UI/Win32K interactions to let an authorized attacker elevate privileges, impacting multiple Windows 10/11 and Windows Server versions.
What to do now
- Check which Windows 10/11 or Windows Server versions you run and whether they are installed with the corresponding fixed build numbers below.
- If you are on an affected Windows 10 build, update to one of these fixed versions: 10.0.14393.9512, 10.0.17763.9245, 10.0.19044.7725, or 10.0.19045.7725.
- If you are on an affected Windows 11 build, update to one of these fixed versions: 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, or 10.0.28000.2954.
- If you are on affected Windows Server, update to the fixed versions: Windows Server 2012 → 6.2.9200.26349; Windows Server 2012 R2 → 6.3.9600.23397; Windows Server 2016 → 10.0.14393.9512; and (for the other listed server versions) 10.0.17763.9245 where applicable for Windows Server 2019.
- After patching, verify the installed build number matches the fixed version for your branch, then confirm security updates are current across all machines.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-68880 and every CVE in our database. Create a free account — no credit card required.
Create Free Account