CVE-2026-83939
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Description
Untrusted pointer dereference in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowCVE-2026-83939 is a Windows 11 security flaw that can let an attacker gain higher privileges, but it generally requires an attacker who already has some local access—so most small businesses should patch promptly, especially on machines exposed to users or unmanaged devices.
CVE-2026-83939 is a local privilege escalation weakness in Windows Secure Kernel Mode caused by an untrusted pointer dereference, allowing an authorized attacker to elevate privileges; Windows 11 is fixed in 10.0.28000.2954.
What to do now
- Check whether the affected device is running Windows 11 and compare your installed build/version to 10.0.28000.2954.
- If you are on an earlier Windows 11 version, install the Microsoft update that fixes CVE-2026-83939.
- After updating, verify the device reports it is fully up to date (no pending reboot and the updated build is present).
- Review endpoint sign-in and local activity logs for unusual local admin or privilege changes around the time of any recent incidents.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:HPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
References
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-83939 and every CVE in our database. Create a free account — no credit card required.
Create Free Account