Junglewise Threat Intelligence

CVE-2026-69676: Microsoft Windows Kerberos authentication bypass

CVE-2026-69676 · Severity: high · CVSS 8.8 · Published 2026-09-08

Technologies: Microsoft Windows Kerberos. Vendors: Microsoft.

Executive brief

Windows Kerberos is the core authentication system used by Microsoft Active Directory to verify user and computer identities across enterprise networks. An authenticated attacker can bypass Kerberos security checks through capture-replay attacks, allowing them to execute arbitrary code on networked systems. This could enable lateral movement within an organization or privilege escalation on domain-joined computers.

Technical details

This vulnerability is a capture-replay authentication bypass in the Windows Kerberos implementation. An authorized attacker on the network can intercept and replay Kerberos tokens to bypass authentication checks and gain unauthorized code execution capabilities. The attack requires network access and an existing authenticated context on the domain. Microsoft has released security patches to address this vulnerability; affected systems should be updated immediately to prevent exploitation.

Affected products

  • Microsoft Windows Kerberos <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats