AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-42976

HIGH · CVSS 7.8 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability in the Windows RPC API allows an authorized attacker to exploit missing authentication for critical functions, enabling local privilege escalation. This could lead to unauthorized access and control over the affected system, posing significant risks to sensitive data and system integrity. Organizations using Windows should prioritize addressing this issue to mitigate potential exploitation by malicious insiders or compromised accounts.

CVE
CVE-2026-42976
Severity
HIGH
CVSS
7.8
EPSS
0.21%
Windows

Original NVD Description

Missing authentication for critical function in Windows RPC API allows an authorized attacker to elevate privileges locally.

Related CVEs

Other vulnerabilities affecting the same vendor(s)