Junglewise Threat Intelligence

CVE-2026-69760: Microsoft Windows Kerberos out-of-bounds read

CVE-2026-69760 · Severity: high · CVSS 7.5 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Kerberos is a core authentication system used in enterprise networks to verify user and computer identities. An out-of-bounds memory read flaw allows a remote attacker to crash the Kerberos service, disrupting authentication across affected systems and potentially causing widespread network outages without requiring valid credentials.

Technical details

An out-of-bounds read vulnerability exists in the Windows Kerberos implementation, allowing a remote attacker to trigger a denial of service condition. The vulnerability can be exploited over the network without authentication. The flaw causes the Kerberos service to read beyond allocated memory boundaries, leading to service crashes or unexpected termination. Attack preconditions are minimal—the attacker only needs network connectivity to the Kerberos service port. Microsoft has released patches to address this issue.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats