CVE-2026-27914General(microsoft / windows_10_1607)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_10_1607 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-06-04); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2012windows_server_2016

2 versions affected across 14 products

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-04-14: 1Mentions · 2026-04-15: 1Mentions · 2026-05-15: 1Mentions · 2026-06-04: 2Mentions · 2026-06-05: 1Patch / Workaround · 2026-05-15: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 1Technical Details · 2026-06-04: 104-1404-1505-1506-0406-05
Signal classification4 categories
General
350.0%
Disclosure
116.7%
Patch
116.7%
False Positive
116.7%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-04-141
General1
2026-04-151
Disclosure1
2026-05-151
Patch1
2026-06-042
False Positive1General1
2026-06-051
General1
Full discourse6 posts
  • Filip Dragovic@filip_dragovic
    False Positive

    As someone who reported CVE-2026-27914 I can tell you its not related to MMC console at all. Maybe its new Microsoft tactic to confuse LLM's with incorrect advisories?🤔 😂😂

    Post summary

    The post refutes earlier advisories by claiming CVE-2026-27914 is unrelated to the MMC console, but offers no supporting evidence.

    3131881818.7K
    7.4K followersView on X
  • T-RN-R@HackyBoiiiii
    General

    @filip_dragovic @mrgretzky Strange, the entry for CVE-2026-27914 on the MSRC update guide states that it is in MMC. The entire PatchWatch pipeline uses Microsoft reported component information to find which binary likely maps to the vulnerability. What component was it in if not MMC?

    Post summary

    The tweet asks whether CVE-2026-27914, which the MSRC guide indicates is in MMC, is correctly mapped to that component, indicating uncertainty but providing the component detail.

    11040535
    115 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-45247 2 - CVE-2026-27914 3 - CVE-2017-11882 4 - CVE-2026-45495 5 - CVE-2026-0826 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply enumerates five trending CVEs without providing exploitation details, patches, or technical specifics.

    0002099
    1.7K followersView on X
  • Horsie :)@realhorsie
    Patch

    @tyholms Did a human inspect the output at any point in time? The pre-patch file you diff against is 2 years old. The patch you claim to be for CVE-2026-27914 existed at least as far back as Jan-2026, so that's blatantly false, along with other errors in actual analysis.

    Post summary

    The comment challenges a previous analysis by asserting that the patch for CVE-2026-27914 existed earlier, pointing out errors in the prior claim but not mentioning exploitation or technical details.

    10000203
    7 followersView on X
  • kawn@kawn2020
    General

    #windowsupdate #microsoft つづき ・CVE-2026-27914 7.8 Microsoft 管理コンソール ・CVE-2026-27921 7  Windows TCP/IP ・CVE-2026-32070 7  Windows 共通ログ ファイル システム ドライバー ・CVE-2026-32075 7  Windows ユニバーサル プラグ アンド プレイ (UPnP) デバイス ホスト …

    Post summary

    The tweet merely enumerates several CVEs with their CVSS scores and affected Microsoft components, providing basic technical details but no evidence of exploitation or mitigation.

    1000088
    85 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27914 Improper access control in Microsoft Management Console allows an authorized attacker to elevate privileges locally. https://www.cve.org/CVERecord?id=CVE-2026-27914

    Post summary

    The post discloses CVE-2026-27914, indicating an improper access control flaw in Microsoft Management Console that permits local privilege escalation, and links to the official CVE record for more details.

    00000139
    57.2K followersView on X
CPE platform detail25 entries

25 of 25 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more