Junglewise Threat Intelligence

CVE-2026-69744: Microsoft Windows Kerberos null pointer dereference

CVE-2026-69744 · Severity: high · CVSS 7.5 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Kerberos is the authentication system used to verify user identity in corporate networks. A null pointer dereference vulnerability allows an unauthenticated attacker to crash the authentication service over the network, causing users to be unable to log in or access network resources until the service is restarted.

Technical details

A null pointer dereference vulnerability exists in the Windows Kerberos authentication subsystem, allowing an unauthenticated attacker to send specially crafted network packets that cause the service to crash. The vulnerability is triggered through the network without requiring authentication or user interaction. Successful exploitation results in denial of service against the Kerberos service, disrupting authentication for domain-joined systems. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats