Junglewise Threat Intelligence

CVE-2026-72940: Microsoft Windows Schannel heap buffer overflow

CVE-2026-72940 · Severity: high · CVSS 8.8 · Published 2026-09-08

Executive brief

Windows Schannel is the cryptographic security component used to protect network communications in Windows systems. A heap buffer overflow vulnerability allows an attacker to execute arbitrary code remotely on affected systems with elevated privileges, potentially compromising confidential data and system operations.

Technical details

A heap-based buffer overflow exists in Windows Schannel, Microsoft's TLS/SSL implementation component. The vulnerability can be triggered over the network without authentication, allowing an attacker to corrupt heap memory and achieve arbitrary code execution. The attack vector is network-based with no authentication or user interaction required. A successful exploit grants the attacker code execution in the security context of the affected process, posing a critical risk to system and data integrity. Patches are available from Microsoft.

Affected products

  • Microsoft Windows Schannel

Timeline

  • 2026-09-08: disclosed

References

Related threats