CVE-2026-27928General(microsoft / windows_server_2016)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft windows_server_2016 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_server_2016
  • windows_server_2019
  • windows_server_2022
  • windows_server_2022_23h2

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-04-14); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
windows_server_2016windows_server_2019windows_server_2022windows_server_2022_23h2windows_server_2025

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-14: 2Mentions · 2026-04-15: 1Mentions · 2026-04-17: 1Mentions · 2026-04-20: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-20: 104-1404-1504-1704-20
Signal classification3 categories
General
360.0%
Patch
120.0%
Disclosure
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-142
General1Patch1
2026-04-151
Disclosure1
2026-04-171
General1
2026-04-201
General1
Full discourse5 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    General

    🪟 بيئة أنظمة Microsoft: (هذه الثغرات رغم ان تصنيفها بين High 8.0-8.7، تأثيرها التشغيلي خطير جداً) 🗄️ خدمة Active Directory: ⚠️ الخطر: تنفيذ أوامر عن بُعد (RCE) برقم (CVE-2026-33826). 🔐 بروتوكول Windows Kerberos: ⚠️ الخطر: تصعيد للصلاحيات برقم (CVE-2026-27912). 👋 ميزة Windows Hello: ⚠️ الخطر: تجاوز آلية المصادقة في Windows Hello برقم (CVE-2026-27928).

    Post summary

    The message lists three high‑severity CVEs—CVE‑2026‑33826 (RCE in Active Directory), CVE‑2026‑27912 (privilege escalation in Kerberos), and CVE‑2026‑27928 (auth bypass in Windows Hello)—but provides no details on hacks, exploit tools, active attacks, patches, or mitigations.

    000451.6K
    49.3K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    General

    رقم الثغرة: CVE-2026-27928 | التقييم: 8.7 (High). ⚠️ تأثير الثغره: تخطي آليات المصادقة الأمنية (Security Feature Bypass) عبر الشبكة دون الحاجة لأي صلاحيات مسبقة.

    Post summary

    The text announces CVE‑2026‑27928, assigns it a CVSS score of 8.7, and describes it as a network‑based authentication bypass, without any evidence of PoC, exploitation, or mitigation.

    110511.4K
    49.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27928 Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network. https://www.cve.org/CVERecord?id=CVE-2026-27928

    Post summary

    CVE‑2026‑27928 is a newly disclosed Windows Hello vulnerability where improper input validation permits attackers to bypass the security feature via the network.

    00000140
    57.2K followersView on X
  • Red Hornet Intel@RedHornet_Intel
    Patch

    CVE-2026-27928 | Microsoft Windows Server 2016 | Vulnerability Description Improper input validation in Windows Hello allows unauth attackers to bypass a security feature over a network by sending malformed input, enabling unauthorized access to protected functionality. Severity: High Exploitation: Unknown Public PoC: Unknown Patch Available: Yes Affected Product: Microsoft Windows Server 2016 Affected Version: >= 10.0.14393.0 and < 10.0.14393.9060 Sources Vendor: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27928

    Post summary

    The post reports a high‑severity Windows Hello flaw in Windows Server 2016, confirms no known exploitation or PoC, and notes a patch is available.

    0000084
    8 followersView on X
  • VulDB 🛡@vuldb
    General

    There is a new vulnerability with elevated criticality in Microsoft Windows (CVE-2026-27928) https://vuldb.com/vuln/357451

    Post summary

    The post announces a new Microsoft Windows vulnerability (CVE-2026-27928) with elevated criticality but provides no further technical details, proof of concept, or evidence of exploitation.

    0000086
    2.1K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more