CVE-2026-20929Disclosure(microsoft / windows_10_1607)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper access control in Windows HTTP.sys allows an authorized attacker to elevate privileges over a network.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-04-01); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_server_2008windows_server_2012windows_server_2016windows_server_2019windows_server_2022

2 versions affected across 11 products

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-03-31: 1Mentions · 2026-04-01: 2Mentions · 2026-04-05: 1Mentions · 2026-04-09: 1Mentions · 2026-04-12: 1Mentions · 2026-06-05: 1Patch / Workaround · 2026-04-12: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 2Technical Details · 2026-04-05: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-12: 1Technical Details · 2026-06-05: 103-3104-0104-0504-0904-1206-05
Signal classification3 categories
Disclosure
457.1%
General
228.6%
Patch
114.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-311
Disclosure1
2026-04-012
Disclosure1General1
2026-04-051
General1
2026-04-091
Disclosure1
2026-04-121
Patch1
2026-06-051
Disclosure1
Full discourse7 posts
  • DirectoryRanger@DirectoryRanger
    General

    Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse https://www.crowdstrike.com/en-us/blog/detecting-kerberos-relay-attack-via-dns-cname-abuse/

    Post summary

    The article highlights detection of CVE‑2026‑20929, a Kerberos authentication relay via CNAME abuse, providing technical details but no evidence of exploitation, PoC, or patch information.

    014055343.6K
    36.7K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-20929 (CVSS 7.5) enables Kerberos authentication relay to AD CS via DNS CNAME abuse, bypassing NTLM protections. CrowdStrike detection monitors for anomalous cert-based auth + unusual AD CS access patterns. #DFIR_Radar https://t.co/YKHJtsUJQK

    Post summary

    The tweet announces CVE‑2026‑20929, detailing its high‑severity nature and exploitation vector (Kerberos relay via DNS CNAME abuse), while noting CrowdStrike’s detection of anomalous authentication patterns.

    11030296
    1.7K followersView on X
  • NerdieNews@NewsNerdie
    Patch

    CVE-2026-20929 allows attackers to exploit Kerberos via CNAME abuse, leading to authentication relay attacks. This vulnerability bypasses existing defenses—patch now to prevent unauthorized access. #NerdieNews #CyberSecurity #InfoSec #ThreatIntel #APT https://t.co/Hi4LEb2osP

    Post summary

    The tweet announces CVE-2026-20929, highlights its Kerberos-based CNAME abuse leading to authentication relay attacks, and urges users to apply the patch to prevent unauthorized access.

    0001045
    55 followersView on X
  • Alexei Belous@AlexeiBelous
    Disclosure

    ADCS ESC8: skipping EPA=Required keeps NTLM relay open. CVE-2026-20929 adds Kerberos CNAME relay to the same endpoint - no NTLM needed. Detection: Event 4886 within seconds of auth from unexpected IP. T1649→T1003.006. Two blind spots, one chain to domain compromise.

    Post summary

    The text discloses technical details of CVE-2026-20929, describing a Kerberos CNAME relay vulnerability, detection methods, and potential attack chains, without presenting a PoC, exploit code, or patch information.

    0000043
    7 followersView on X
  • DNSAudit.io@dnsaudit
    Disclosure

    🚩 CVE-2026-20929: Turning Kerberos into a Relay Vector via DNS https://www.crowdstrike.com/en-us/blog/detecting-kerberos-relay-attack-via-dns-cname-abuse/ CVE-2026-20929 shows how DNS CNAME abuse can turn Kerberos into a relay vector, even in environments where NTLM is disabled. By targeting AD CS, attackers can issue certificates for user accounts and gain long-term access without relying on passwords. Detection now focuses on correlating unusual certificate authentication with abnormal service access patterns. If missed, this can lead to persistent, stealthy compromise inside Active Directory environments. #DNS #DNSSecurity #InfoSec

    Post summary

    The article announces CVE‑2026‑20929, explaining how DNS CNAME abuse can transform Kerberos into a relay vector and outlines detection strategies, but no exploits, patches, or active attack reports are mentioned.

    0000050
    13 followersView on X
  • Tech4Index@tech4index
    General

    Detecting CVE-2026-20929: Kerberos Relay via CNAME Abuse ⭕️ Researchers identify methods to detect Kerberos authentication relay exploiting CNAME abuse. https://t.co/IENRDOdfrA

    Post summary

    Researchers have published detection methods for CVE-2026-20929, a Kerberos relay vulnerability via CNAME abuse, but the post provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000027
    70 followersView on X
  • ThreatLevel@ThreatLevelLabs
    Disclosure

    🚨 CVE-2026-20929 Kerberos relay via DNS CNAME (HTTP.sys) (Credential relay / auth-bypass) Microsoft Windows HTTP.sys (HTTP Server API) | CVSS 7.5 | Auth https://threatlevel.io/CVE-2026-20929 #EmergencyFix #CVE #cybersecurity

    Post summary

    The tweet announces CVE-2026-20929, a Windows HTTP.sys vulnerability that permits Kerberos credential relay via DNS CNAME, rated CVSS 7.5, but it provides no PoC, exploit, or mitigation information.

    0000067
CPE platform detail16 entries

16 of 16 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_server_2008--x64
OSmicrosoftwindows_server_2008--x86
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---

Explore more