CVE-2026-69890
Windows Virtual Trusted Platform Module Elevation of Privilege Vulnerability
Description
Use after free in Windows Virtual Trusted Platform Module allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowThis is a Windows local privilege-escalation flaw that affects Windows 10/11 and Windows Server editions; small businesses should patch quickly if you have administrative users or untrusted staff/accounts, because it’s the kind of bug that can turn limited access into full control.
CVE-2026-69890 is a Windows Virtual Trusted Platform Module elevation of privilege issue (CWE-416) caused by a use-after-free condition that can let an authorized attacker gain higher privileges locally on affected Windows versions; the CISA KEV list does not show this as a known actively exploited issue.
What to do now
- Check whether your organization runs any of these affected products: Windows 10, Windows 11, Windows Server 2019, Windows Server 2022, or Windows Server 2025.
- Identify the exact OS version/build number and compare it against the vendor-fixed build numbers listed below.
- Upgrade/patch each affected device to a fixed version: Windows 10 fixed in 10.0.17763.9245, 10.0.19044.7725, or 10.0.19045.7725; Windows 11 fixed in 10.0.22631.7582, 10.0.26100.9445, 10.0.26200.9445, or 10.0.28000.2954; Windows Server 2019 fixed in 10.0.17763.9245; Windows Server 2022 fixed in 10.0.20348.5622; Windows Server 2025 fixed in 10.0.26100.33438.
- If immediate patching isn’t possible, restrict who can sign in with local administrative privileges and reduce access from untrusted or temporary accounts while you patch.
CVSS Vector Breakdown
AV:LAttack VectorAC:HAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-69890 and every CVE in our database. Create a free account — no credit card required.
Create Free Account