Junglewise Threat Intelligence

CVE-2026-65777: Microsoft Windows Active Directory inadequate encryption strength bypass

CVE-2026-65777 · Severity: medium · CVSS 5.3 · Published 2026-08-11

Vendors: Microsoft.

Executive brief

Windows Active Directory, a core directory service that manages user identities and access control across enterprise networks, contains a weakness in its encryption implementation. An authorized attacker on the network could exploit this flaw to bypass a security feature, potentially compromising access controls or exposing sensitive authentication data.

Technical details

This vulnerability stems from inadequate encryption strength in Windows Active Directory's security mechanisms. An authorized attacker with network access can bypass a security feature by exploiting weak encryption parameters. The attack requires prior authorization to the system and network reachability. Successful exploitation could lead to circumvention of intended security controls. A patch is available from Microsoft.

Affected products

  • Microsoft Windows Active Directory <UNKNOWN>

Timeline

  • 2026-08-11: disclosed

References