CVE-2026-27912PoC(microsoft / windows_server_2012)

MEDIUMCVSS 8.0 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_server_2012 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_server_2012
  • windows_server_2016
  • windows_server_2019
  • windows_server_2022

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 26 mentions across 15 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 10 signals
  • PoC mentioned or linked in 16 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 16 signals
  • Disclosure: 4 classified signals
  • Peaked 8d ago at 4 mentions (2026-08-10); latest day: 1
  • 26 total mentions across 15 days

Affected systems

Vendors
Products
windows_server_2012windows_server_2016windows_server_2019windows_server_2022windows_server_2022_23h2windows_server_2025

2 versions affected across 6 products

Deep dive

Activity timeline26 mentions / 15d
01234Mentions · 2026-04-15: 1Mentions · 2026-04-17: 1Mentions · 2026-04-19: 1Mentions · 2026-08-07: 2Mentions · 2026-08-08: 2Mentions · 2026-08-09: 3Mentions · 2026-08-10: 4Mentions · 2026-08-11: 2Mentions · 2026-08-12: 1Mentions · 2026-08-13: 3Mentions · 2026-08-15: 1Mentions · 2026-08-18: 2Mentions · 2026-08-21: 1Mentions · 2026-09-07: 1Mentions · 2026-09-11: 1PoC Mentioned / Linked · 2026-08-07: 2PoC Mentioned / Linked · 2026-08-08: 1PoC Mentioned / Linked · 2026-08-09: 1PoC Mentioned / Linked · 2026-08-10: 3PoC Mentioned / Linked · 2026-08-11: 2PoC Mentioned / Linked · 2026-08-12: 1PoC Mentioned / Linked · 2026-08-13: 3PoC Mentioned / Linked · 2026-08-15: 1PoC Mentioned / Linked · 2026-08-21: 1PoC Mentioned / Linked · 2026-09-11: 1Exploit Tool / Code · 2026-08-07: 2Exploit Tool / Code · 2026-08-08: 1Exploit Tool / Code · 2026-08-09: 1Exploit Tool / Code · 2026-08-10: 3Exploit Tool / Code · 2026-08-11: 1Exploit Tool / Code · 2026-08-15: 1Exploit Tool / Code · 2026-08-21: 1Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-08-08: 1Patch / Workaround · 2026-08-10: 1Patch / Workaround · 2026-08-11: 1Patch / Workaround · 2026-09-07: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-19: 1Technical Details · 2026-08-07: 2Technical Details · 2026-08-09: 2Technical Details · 2026-08-10: 3Technical Details · 2026-08-11: 2Technical Details · 2026-08-13: 1Technical Details · 2026-08-18: 1Technical Details · 2026-08-21: 1Technical Details · 2026-09-07: 104-1504-1704-1908-0708-0808-0908-1008-1108-1208-1308-1508-1808-2109-0709-11
Signal classification5 categories
PoC
1038.5%
Exploit
519.2%
Disclosure
415.4%
General
415.4%
Patch
311.5%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-04-151
Disclosure1
2026-04-171
General1
2026-04-191
Disclosure1
2026-08-072
PoC2
2026-08-082
Patch1PoC1
2026-08-093
Disclosure1General1PoC1
2026-08-104
Exploit2PoC2
2026-08-112
Patch1PoC1
2026-08-121
Exploit1
2026-08-133
Exploit1General1PoC1
2026-08-151
PoC1
2026-08-182
Disclosure1General1
2026-08-211
Exploit1
2026-09-071
Patch1
2026-09-111
PoC1
Full discourse20 posts
  • Azox@azoxlpf
    Exploit

    Exploit ResetNightmare with NetExec 🔥 CVE-2026-27912: a logical flaw in the Kerberos Change Password protocol lets an attacker with Generic Write on one account reset the password of ANY user/computer, including Domain Admins. Built a module to automate the full chain 🚀 https://t.co/G1t970xBpp

    Post summary

    The post highlights an exploit for CVE-2026‑27912, describing a logical flaw that lets an attacker reset any password, and references a module to automate the attack.

    363028514714.8K
    313 followersView on X
  • Swissky@pentest_swissky
    PoC

    Exploiting AD ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177) from Linux - @rouge_cravate https://cravaterouge.com/articles/resetnightmare/

    Post summary

    The post announces the exploitation of two Linux-related CVEs (ResetNightmare and KerberLoss) and references an article that presumably contains a proof‑of‑concept implementation.

    045019416212.8K
    23.1K followersView on X
  • Azox@azoxlpf
    Patch

    Yeah for those asking: NetExec now detects CVE-2026-27912 (ResetNightmare) via the enum_cve module. Patch or check exposure 🚀 https://t.co/hLmmrRtZrs

    Post summary

    NetExec detected CVE‑2026‑27912 (ResetNightmare) and the post indicates a patch is available or that exposure should be checked.

    05312269525.9K
    313 followersView on X
  • yousukezan@yousukezan
    Patch

    WindowsのKerberos Change Passwordプロトコルに、元のパスワードを知らずに任意のActive Directoryアカウントのパスワードを変更できる脆弱性「ResetNightmare」が公開された。CVE-2026-27912として追跡され、PoCも公開されている。 攻撃者は、自身が制御するアカウントのuserPrincipalName(UPN)を書き換えられる権限、または新規アカウント作成権限を必要とする。まず自身のUPNを「Administrator」など標的のsAMAccountNameに設定し、NT-ENTERPRISE形式でその名前のTGTを取得する。 その後、自身のUPNを消去して取得済みチケットを使用すると、標的アカウントの元のパスワードを知らなくてもパスワードをリセットできる。Microsoftによると、悪用に成功した攻撃者はSYSTEM権限を取得できる可能性がある。 影響するのは更新されていないWindowsドメインコントローラーで、攻撃には同じ制限されたActive Directoryドメイン内からのアクセスが必要となる。Microsoftは2026年4月のPatch Tuesdayで修正した。Semperisは攻撃手順を自動化するResetNightmareのPoCをGitHubで公開しており、現時点で実際の悪用は確認されていない。 https://securityonline.info/cve-2026-27912-resetnightmare-kerberos-system/

    Post summary

    CVE‑2026‑27912 (ResetNightmare) allows password resets without the original password; a PoC exists and Microsoft patched the flaw in April 2026, though no active exploitation has been reported.

    044014710911.7K
    16.0K followersView on X
  • ThreatWire@ThreatWire_
    PoC

    🚨 PoC released: CVE-2026-27912, a Windows Kerberos privilege escalation vulnerability, now has a public exploit. The flaw affects Windows Server 2012 and allows an authorized attacker to elevate privileges over an adjacent network. PoC: https://github.com/semperis-community/resetnightmare #Microsoft #Windows #Kerberos #CVE #PoC #CyberSecurity #ActiveDirectory #Infosec

    Post summary

    A Proof-of-Concept with a public exploit for CVE-2026-27912, a Kerberos privilege escalation flaw targeting Windows Server 2012, has been released, though no evidence of active exploitation is reported.

    325088468.1K
    1.7K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Proof-of-concept (POC) tool for ResetNightmare (CVE-2026-27912). https://github.com/semperis-community/resetnightmare

    Post summary

    A proof‑of‑concept tool has been released on GitHub for the ResetNightmare vulnerability (CVE‑2026‑27912).

    029096326.7K
    162.1K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🚨 Windows Kerberos'ta bulunan CVE-2026-27912 numaralı privilege escalation açığı için PoC Exploit yayınlandı. Açık, Windows Server 2012–2025 arası birçok sürümü etkiliyor ve saldırganın ağ üzerinden ayrıcalıklarını yükseltmesine olanak tanıyor. https://github.com/semperis-community/resetnightmare

    Post summary

    A PoC exploit for privilege escalation via CVE‑2026‑27912 has been released on GitHub, but there is no indication of active exploitation or available patch.

    111050453.3K
    2.4K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    🚨 ثغرة جديده في انظمه ويندوز الثغره في بروتوكول المصادقة (Windows Kerberos). رقم الثغرة: CVE-2026-27912 | التقييم: 8.0 (High). ⚠️الثغره تسمح لأي مهاجم يمتلك حساباً عادياً برفع صلاحياته (EoP) بشكل غير مصرح به داخل الدومين. المشكله في ضعف التحقق من الصلاحيات (Improper Authorization) عند معالجة طلبات Kerberos. المهاجم يتلاعب ببيانات التوثيق عشان يتجاوز ضوابط الوصول والحصول على امتيازات عاليه. متطلبات الاستغلال: 📍حساب مستخدم دومين عادي (Low Privileges). 📍لا يتطلب تفاعل من الضحية. 📍 يتطلب اتصالاً بالشبكة الداخلية للمؤسسة (Adjacent Network - LAN/VPN). 🪟 الأنظمة المتأثرة : جميع إصدارات Windows Server المتأثرة (من 2012 R2 وحتى 2025). أصدرت Microsoft تحديث لمعالجة الثغرة في حزمة Patch Tuesday (بتاريخ 14 أبريل 2026). حتى الآن، لا يوجد استغلال علني للثغره لكن مايكروسفت تقول ان الثغره قد تكون قابله للاستغلال قريباً

    Post summary

    The post announces CVE‑2026‑27912, a high‑severity Windows Kerberos privilege‑escalation flaw, notes the Microsoft patch released on 14 April 2026, and confirms no public exploitation yet.

    081563339.6K
    49.3K followersView on X
  • Cristian Borghello@SeguInfo
    Exploit

    ResetNightmare: exploit público permite restablecer cualquier contraseña de cuenta de AD (CVE-2026-27912) http://blog.segu-info.com.ar/2026/08/resetnightmare-exploit-publico-permite.html

    Post summary

    The post announces a public exploit for CVE-2026-27912 that can reset any AD account password, but it lacks details on patching, technical specifics, or evidence of active exploitation.

    016049234.3K
    38.3K followersView on X
  • dbugs@ptdbugs
    PoC

    A PoC/exploit has been discovered for vulnerability CVE-2026-27912 Vendor: Microsoft Product: Windows Server 2012 Description: Improper authorization in Windows Kerberos allows an authorized attacker to elevate privileges over an adjacent network. Link: https://github.com/semperis-community/resetnightmare #dbugs_vuln

    Post summary

    A proof‑of‑concept and exploit for CVE‑2026‑27912 were published on GitHub, detailing a privilege‑elevation flaw in Windows Kerberos, but no evidence of active exploitation or patch status is mentioned.

    0602892.0K
    3.6K followersView on X
  • IT-Connect.fr@ITConnect_fr
    General

    ResetNightmare : cette faille Kerberos permet de prendre le contrôle du domaine Active Directory Découvrez mon article à ce sujet 👇 https://www.it-connect.fr/resetnightmare-cve-2026-27912-kerberos-active-directory/ #cybersecurite #activedirectory #sysadmin https://t.co/GRRwl9N0RV

    Post summary

    A tweet promotes an article about the ResetNightmare Kerberos vulnerability (CVE‑2026‑27912) that could let attackers seize control of an Active Directory domain.

    01201651.2K
    11.7K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    Details and PoC for CVE-2026-27912 (ResetNightmare) are public. This Kerberos flaw lets attackers reset AD passwords and gain SYSTEM. #CVE202627912 #ResetNightmare #Kerberos #ActiveDirectory #PrivilegeEscalation #InfoSec http://securityonline.info/cve-2026-27912-resetnightmare-kerberos-system/

    Post summary

    CVE-2026-27912 (ResetNightmare) is a Kerberos vulnerability that enables privileged password resets and SYSTEM acquisition; its details and PoC have been publicly released, with no active exploitation or patch information reported.

    050117830
    13.0K followersView on X
  • @Cravaterouge.infosec.exchange@rouge_cravate
    PoC

    Exploit demo on Linux and Patch Analysis of ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177), two Active Directory vulnerabilities discovered by Shai Laron from @SemperisTech allowing Full Domain Takeover and more. https://cravaterouge.com/articles/resetnightmare/

    Post summary

    The post announces an exploit demonstration for two Active Directory CVEs and references patch analysis, but lacks evidence of live exploitation.

    060841.3K
    330 followersView on X
  • blueblue@piedpiper1616
    PoC

    GitHub - Semperis-Community/ResetNightmare: POC tool for ResetNightmare (CVE-2026-27912) · GitHub - https://github.com/Semperis-Community/ResetNightmare

    Post summary

    The provided GitHub repository hosts a proof‑of‑concept tool for CVE‑2026‑27912, demonstrating the ResetNightmare vulnerability, but offers no evidence of active exploitation, patches, or detailed technical data.

    04033885
    5.5K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    General

    🪟 بيئة أنظمة Microsoft: (هذه الثغرات رغم ان تصنيفها بين High 8.0-8.7، تأثيرها التشغيلي خطير جداً) 🗄️ خدمة Active Directory: ⚠️ الخطر: تنفيذ أوامر عن بُعد (RCE) برقم (CVE-2026-33826). 🔐 بروتوكول Windows Kerberos: ⚠️ الخطر: تصعيد للصلاحيات برقم (CVE-2026-27912). 👋 ميزة Windows Hello: ⚠️ الخطر: تجاوز آلية المصادقة في Windows Hello برقم (CVE-2026-27928).

    Post summary

    The post lists three high‑severity CVEs affecting Microsoft Active Directory, Kerberos, and Windows Hello, noting their impact types but providing no proof of exploitation, PoC, or patch information.

    000451.6K
    49.3K followersView on X
  • 0patch@0patch
    Patch

    Micropatches released for "ResetNightmare" Windows Kerberos Elevation of Privilege (CVE-2026-27912) https://0patch.com/blog/micropatches-released-for-resetnightmare-windows-kerberos-elevation-of-privilege https://t.co/gn3kHBnr3L

    Post summary

    Micropatches have been released to mitigate CVE‑2026‑27912, a Windows Kerberos elevation‐of‐privilege vulnerability, with details and resources linked in the tweet.

    12021535
    8.4K followersView on X
  • nt!RajKit@NtRajkit
    Exploit

    https://kdrajkit.github.io/blogs/windows-internals/ResetNightmare-CVE-2026-27912/

    Post summary

    The blog introduces CVE‑2026‑27912 (ResetNightmare), offers technical details and a full exploit script, but does not report any active exploitation or patch availability.

    1104046.2K
    17 followersView on X
  • Chain Recon@AgenticChain
    Exploit

    Can Generic Write really reset Domain Admins? 1 Generic Write edge can become password resets for any user/computer, including DAs: CVE-2026-27912, Kerberos Change Password. NetExec now automates it. Review Generic Write exposure first.

    Post summary

    The post highlights that a Generic Write vulnerability (CVE‑2026‑27912) can reset Domain Admin passwords and that NetExec can automate this attack, but does not report active exploitation or patching.

    0102015
    478 followersView on X
  • mRr3b00t@UK_Daniel_Card
    General

    @ThreatWire_ * affects way more than just server 2012 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27912

    Post summary

    The tweet merely references a CVE ID and a Microsoft update page without providing further technical or exploit details.

    00010243
    126.0K followersView on X
  • Mahmoud Jadaan@mjadaaan
    PoC

    CVE-2026-27912: PoC for ResetNightmare https://github.com/semperis-community/resetnightmare

    Post summary

    The post announces a proof‑of‑concept for CVE‑2026‑27912 (ResetNightmare) and provides a GitHub link to the code.

    00010192
    42 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more