CVE-2026-0872General

LOWCVSS 2.5 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoofing by Improper Validation. This issue affects SafeNet Agent for Windows Logon: 4.0.0, 4.1.1, 4.1.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-02-13)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-05: 1Mentions · 2026-02-13: 2Patch / Workaround · 2026-02-05: 1Technical Details · 2026-02-05: 1Technical Details · 2026-02-13: 102-0502-13
Signal classification2 categories
General
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-051
Patch1
2026-02-132
General2
Full discourse3 posts
  • Netwrix@Netwrix
    Patch

    Netwrix Security Research, led by Huy Kha, identified an ESC1 privilege escalation path in certain versions of SafeNet Agent for Windows Logon. The issue, tracked as CVE-2026-0872, stemmed from an insecure AD CS certificate template configuration that allowed any authenticated user to escalate to Domain Admin. Read the blog to learn about the CVE and the recommended mitigation 👉https://netwrix.com/en/resources/blog/how-i-got-domain-admin-via-safenet-agent-for-windows-logon-through-esc1/?cID=701Qk00000TfcKSIAZ&utm_source=smm&utm_medium=twitter&utm_campaign=product-demo #Netwrix #IdentitySecurity #DataSecurity #SecurityResearch

    Post summary

    The post announces CVE-2026-0872, a privilege escalation flaw in SafeNet Agent for Windows Logon, and directs readers to mitigation steps, with no PoC, active exploitation, or false‑positive claims reported.

    11030262
    2.9K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-0872 Improper Certificate Validation vulnerability in Thales SafeNet Agent for Windows Logon on Windows allows Signature Spoofing by Improper Validation.This issue affects S… https://www.cve.org/CVERecord?id=CVE-2026-0872

    Post summary

    The text briefly announces that Thales SafeNet Agent for Windows Logon has an improper certificate validation flaw that could lead to signature spoofing, with no evidence of exploitation or remediation.

    00020497
    56.5K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-0872 📊 Severity: 2.5 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-0872 #CVE-2026-0872 #CVE #Low #CyberSecurity #InfoSec https://t.co/SRK8gkWtUg

    Post summary

    The tweet merely announces CVE-2026-0872 as a low-severity issue, offering no technical details, PoC, exploitation evidence, or mitigation information.

    0000048
    57 followersView on X

Explore more