CVE-2026-0828PoC

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Kernel driver ProcessMonitorDriver.sys in Safetica's endpoint client x64 , versions 10.5.75.0 and 11.11.4.0, allows unprivileged user to abuse IOCTL path and terminate protected system processes.

3.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 5 signals
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-02-14); latest day: 1
  • 8 total mentions across 6 days

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-02-04: 1Mentions · 2026-02-06: 1Mentions · 2026-02-14: 2Mentions · 2026-02-16: 1Mentions · 2026-04-02: 2Mentions · 2026-04-06: 1PoC Mentioned / Linked · 2026-02-04: 1PoC Mentioned / Linked · 2026-02-06: 1PoC Mentioned / Linked · 2026-02-14: 1PoC Mentioned / Linked · 2026-04-02: 1PoC Mentioned / Linked · 2026-04-06: 1Exploit Tool / Code · 2026-02-06: 1Exploit Tool / Code · 2026-02-14: 1Exploit Tool / Code · 2026-04-06: 1Technical Details · 2026-04-02: 2Technical Details · 2026-04-06: 102-0402-0602-1402-1604-0204-06
Signal classification3 categories
PoC
450.0%
General
225.0%
Disclosure
225.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-041
PoC1
2026-02-061
PoC1
2026-02-142
General1PoC1
2026-02-161
General1
2026-04-022
Disclosure1PoC1
2026-04-061
Disclosure1
Full discourse8 posts
  • Co11ateral@co11ateral
    Disclosure

    Breaking Process Protection: Exploiting CVE-2026-0828 in ProcessMonitorDriver.sys A recently disclosed vulnerability CVE-2026-0828 in the Windows kernel driver ProcessMonitorDriver.sys showed that any user-mode application that obtains a handle to the device can terminate arbitrary processes, including protected system processes, without proper access-control checks. This flaw effectively bypasses the normal Windows security model that protects critical system services and security components https://core-jmp.org/2026/04/breaking-process-protection-exploiting-cve-2026-0828-in-processmonitordriver-sys/

    Post summary

    The article is a disclosure of CVE-2026-0828, a Windows kernel driver flaw allowing arbitrary process termination via device handles, with no PoC, exploit code, patches, or active exploitation mentioned.

    19027131.6K
    7.8K followersView on X
  • Syed Wajeeh@SyedWaj25802383
    PoC

    @anylink20240604 Full Research & PoC: https://github.com/DeathShotXD/0xKern3lCrush-Foreverday-BYOVD-CVE-2026-0828

    Post summary

    The tweet announces research and a PoC for CVE-2026-0828, linking to a GitHub repository containing the proof‑of‑concept code.

    01034505
    13 followersView on X
  • Syed Wajeeh@SyedWaj25802383
    PoC

    Game over for Windows? 🏛️♟️ 0xKern3lCrush checkmates the "Trust" model. BYOVD makes PPL a joke. Documenting how Safetica (CVE-2026-0828) & ThrottleStop (CVE-2025-7771) become kernel sledgehammers. 0xArtifacts: 👉 https://github.com/DeathShotXD/0xKern3lCrush-Foreverday-BYOVD-CVE-2026-0828 #InfoSec #BYOVD #redteam #EthicalHacking https://t.co/740P4RGdhm

    Post summary

    The tweet announces a GitHub repository containing a Proof of Concept that demonstrates how CVE-2026-0828 and CVE-2025-7771 can be exploited as kernel‑level attacks.

    01020130
    13 followersView on X
  • AnMioLink@anylink20240604
    General

    And...Is it the same with CVE-2026-0828?

    Post summary

    The text only asks a question about CVE‑2026‑0828 with no additional details or claims.

    00011585
    357 followersView on X
  • Hacking Team@HackingTeam77
    Disclosure

    Una vulnerabilidad recientemente revelada, CVE-2026-0828, en el controlador del núcleo de Windows ProcessMonitorDriver.sys pone de manifiesto una capacidad peligrosa: cualquier aplicación en modo usuario que obtenga un identificador del dispositivo puede finalizar procesos arbitrarios, incluidos los procesos protegidos del sistema, sin que se realicen las comprobaciones de control de acceso adecuadas. Esta falla elude de hecho el modelo de seguridad habitual de Windows que protege los servicios críticos del sistema y los componentes de seguridad. https://github.com/oxfemale/KillChain #maldev #github #killprocess

    Post summary

    The post announces CVE-2026-0828, detailing its ability to kill protected system processes via missing access checks, links to a GitHub repository containing a likely PoC, but makes no reference to active exploitation, patches, or false-positive claims.

    00001227
    1.3K followersView on X
  • AnMioLink@anylink20240604
    General

    Current vulnerability has two CVE IDs: CVE-2025-70795 and CVE-2026-0828. This post may update when the final ID come out.

    Post summary

    The post simply lists two CVE IDs for an unspecified vulnerability, providing no further technical or remediation details.

    00010152
    357 followersView on X
  • Syed Wajeeh@SyedWaj25802383
    PoC

    @Salsa12__ https://github.com/DeathShotXD/0xKern3lCrush-Foreverday-BYOVD-CVE-2026-0828/tree/main

    Post summary

    The tweet shares a GitHub link to a repository that appears to contain a proof‑of‑concept or exploit for CVE-2026-0828.

    0001057
    13 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    PoC

    🚨 KillChain Exploit: New #CVE-2026-0828 Lets Attackers Terminate ANY #Windows Process – Including Protected Services! + Video https://undercodetesting.com/killchain-exploit-new-cve-2026-0828-lets-attackers-terminate-any-windows-process-including-protected-services-video/ Educational Purposes!

    Post summary

    The tweet highlights a new CVE that lets attackers terminate any Windows process and links to a video demonstrating the exploit, but it does not provide exploit code, active exploitation reports, or patch information.

    0000037
    452 followersView on X

Explore more