CVE-2026-69846
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Description
Integer overflow or wraparound in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowCVE-2026-69846 is a Windows local privilege escalation bug that lets an attacker with an account on the machine gain higher privileges; if your business computers are not fully up to date, you should act now.
CVE-2026-69846 is a local privilege escalation flaw in Windows Secure Kernel Mode (CWE-190) where an integer overflow/wraparound can let an authorized attacker elevate privileges on the affected Windows versions.
What to do now
- Check whether any affected device is on an unpatched Windows build by viewing the installed OS version/build number (Settings → System → About, or winver).
- Match that build to the vendor’s fixed build list and confirm it is at-or-above the corresponding fixed version for your edition (Windows 10/11 or Server).
- Install the latest available Windows security updates, then re-check the build number until it reaches the fixed version for your branch:
- Windows 10: 10.0.14393.9512 / 10.0.17763.9245 / 10.0.19044.7725 / 10.0.19045.7725
- Windows 11: 10.0.22631.7582 / 10.0.26100.9445 / 10.0.26200.9445 / 10.0.28000.2954
- Windows Server 2016: 10.0.14393.9512
- Windows Server 2019: 10.0.17763.9245
- Windows Server 2022: 10.0.20348.5622
- Windows Server 2025: 10.0.26100.33438
- If you can’t patch immediately, restrict local logins and tighten access to endpoints (especially admin/privileged accounts) while you schedule the update rollout.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-69846 and every CVE in our database. Create a free account — no credit card required.
Create Free Account