CVE-2026-27906Disclosure(microsoft / windows_10_21h2)

MEDIUMCVSS 4.4 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft windows_10_21h2 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_21h2
  • windows_10_22h2
  • windows_11_23h2
  • windows_11_24h2

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-14); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-14: 1Mentions · 2026-04-17: 1Mentions · 2026-04-23: 1Active Exploitation · 2026-04-23: 1Patch / Workaround · 2026-04-23: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-23: 104-1404-1704-23
Signal classification2 categories
Disclosure
266.7%
Active Exploitation
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-04-141
Disclosure1
2026-04-171
Disclosure1
2026-04-231
Active Exploitation1
Full discourse3 posts
  • kawn@kawn2020
    Disclosure

    #windowsupdate #microsoft つづき ・CVE-2026-26169 6.1 Windows カーネル メモリ ・CVE-2026-27906 4.4 Windows Hello ・CVE-2026-27908 7  Windows TDI 翻訳ドライバー(tdx.sys) ・CVE-2026-27909 7.8 Microsoft Windows 検索コンポーネント ・CVE-2026-27913 7.7 Windows BitLocker …

    Post summary

    The post announces several newly disclosed Windows CVEs, listing affected components and versions but providing no exploitation details or patch information.

    10000189
    85 followersView on X
  • Md. Najeeb Hussain@mnh_18
    Active Exploitation

    🪟 Microsoft April 2026 Patch Tuesday: 167 security flaws fixed — including 2 ZERO-DAYS! 🛡️ This is the SECOND-LARGEST Patch Tuesday in Microsoft's history! Critical fixes you MUST apply: 🔴 CVE-2026-32201 — SharePoint Server ZERO-DAY actively exploited in the wild! 😱 🔴 CVE-2026-33825 — Microsoft Defender privilege escalation (public exploit available!) 🔴 CVE-2026-33824 — Windows IKE: remote code execution via network! Critical! 🔴 CVE-2026-33827 — Windows TCP/IP stack race condition RCE! 🔴 CVE-2026-27906 — Windows Hello security bypass! Also: Secure Boot certificates expiring June 26, 2026 — Microsoft pushing updates NOW! Indian enterprise IT teams 🇮🇳 — patch your SharePoint servers IMMEDIATELY! ⚡ #Microsoft #PatchTuesday #Security #SharePoint #ZeroDay #WindowsSecurity

    Post summary

    Microsoft's April 2026 Patch Tuesday lists two zero-days, notably a SharePoint Server flaw actively exploited in the wild. The post urges immediate patching across affected Microsoft platforms.

    00000109
    179 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27906 Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally. https://www.cve.org/CVERecord?id=CVE-2026-27906

    Post summary

    The brief note announces CVE‑2026‑27906 as an improper input validation flaw in Windows Hello that lets an authorized attacker bypass local security features, but provides no additional details or remediation information.

    00000130
    57.2K followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64

Explore more