← Back

CVE-2026-27928

nvd nist
Published: Apr 14, 2026Modified: Apr 22, 2026

JSON object

Loading...
8.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Exploitability: 2.2 / Impact: 5.8
Source: secure@microsoft.com

Description

Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.

Affected (5)

5 products
Windows Server 2016
Windows Server 2019
Windows Server 2022
Windows Server 2022 23h2
Windows Server 2025
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Before 10.0.14393.9060
Before 10.0.17763.8644
Before 10.0.20348.5020
Before 10.0.25398.2274
Before 10.0.26100.32690

References (1)

Timeline

No history available yet.