SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-40378

HIGH · CVSS 7.5 EPSS 0.82%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

The vulnerability in the Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to exploit excessive memory allocation, leading to potential denial of service over the network. This high-severity issue poses significant risks to system availability and should be prioritized by organizations using Windows systems, particularly those with critical infrastructure or sensitive data. Immediate remediation is recommended to mitigate the risk of service disruption.

CVE
CVE-2026-40378
Severity
HIGH
CVSS
7.5
EPSS
0.82%
Windows

Original NVD Description

Memory allocation with excessive size value in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

Related CVEs

Other vulnerabilities affecting the same vendor(s)