CVE-2026-69498
Windows Win32k Elevation of Privilege Vulnerability
Description
Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowThis is a Windows local privilege-escalation bug that can let someone with access to your device gain higher permissions; small businesses should patch soon, especially on Windows 10/11 and Windows Server systems.
CVE-2026-69498 is a local elevation of privilege in the Windows Win32k subsystem, triggered via a use-after-free condition that can allow an authorized attacker to gain higher privileges; Microsoft provides fixed versions for supported Windows 10/11 and Windows Server releases.
What to do now
- Check which Windows 10, Windows 11, or Windows Server version/build your devices are running.
- Compare your current Windows build number against the Microsoft fixed versions below.
- Update any affected devices to at least: Windows 10 10.0.17763.9245 or 10.0.19044.7725 or 10.0.19045.7725; Windows 11 10.0.22631.7582 or 10.0.26100.9445 or 10.0.26200.9445 or 10.0.28000.2954; Windows Server 2019 10.0.17763.9245; Windows Server 2022 10.0.20348.5622; Windows Server 2025 10.0.26100.33438.
- If you can’t patch immediately, restrict who can log on to the affected machines and reduce exposure of administrator accounts until updates are applied.
CVSS Vector Breakdown
AV:LAttack VectorAC:HAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-69498 and every CVE in our database. Create a free account — no credit card required.
Create Free Account