SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-72931

MEDIUM · CVSS 4.7 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to exploit a failure to release resources after their effective lifetime, potentially leading to a local denial of service. Organizations utilizing Windows systems that implement SSTP should prioritize this issue to mitigate potential disruptions in service availability.

CVE
CVE-2026-72931
Severity
MEDIUM
CVSS
4.7
EPSS
0.25%
Windows

Original NVD Description

Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally.