CVE-2026-40144Patch

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to version 26.1.2. Insufficient validation of input processed by the component may result in memory being accessed outside its intended bounds.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-08-17); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-08-17: 2Mentions · 2026-08-19: 2Mentions · 2026-08-27: 1Patch / Workaround · 2026-08-17: 1Patch / Workaround · 2026-08-19: 2Patch / Workaround · 2026-08-27: 1Technical Details · 2026-08-17: 2Technical Details · 2026-08-19: 1Technical Details · 2026-08-27: 108-1708-1908-27
Signal classification2 categories
Patch
360.0%
Disclosure
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-172
Disclosure2
2026-08-192
Patch2
2026-08-271
Patch1
Full discourse5 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    BeyondTrust patched two high-severity EPM flaws (CVE-2026-40144, CVE-2026-40145) allowing local privilege escalation on Windows. Update to 26.1.2. #BeyondTrust #CVE202640144 #PrivilegeEscalation #Windows #EndpointSecurity #InfoSec https://securityonline.info/beyondtrust-vulnerability-cve-2026-40144/

    Post summary

    BeyondTrust released updates (26.1.2) to patch CVE‑2026‑40144 and CVE‑2026‑40145, which were high‑severity local privilege escalation vulnerabilities on Windows.

    01010417
    12.8K followersView on X
  • iototsecnews@iototsecnews
    Patch

    BeyondTrust Windows EPM の脆弱性 CVE-2026-40144/40145 が FIX:深刻な権限昇格の恐れ https://iototsecnews.jp/2026/08/19/beyondtrust-windows-epm-vulnerabilities-allows-attackers-to-escalate-privileges/ BeyondTrust Endpoint Privilege Management (Windows Deployment) における、特権制御処理に対する非検証の問題が生じています。この脆弱性 CVE-2026-40144/CVE-2026-40145 を悪用する攻撃者により、ローカル端末上での任意コード実行/改ざん防止機能の無効化/最上位権限の奪取といった重大な被害が生じる恐れがあります。対応策として、最新版 26.1.2 以降への更新/カーネル挙動の監視/不審な昇格アクティビティの検知が推奨されます。 #BeyondTrust #CVE202640144 #CVE202640145 #Vulnerability #WindowsEPM

    Post summary

    BeyondTrust CVE‑2026‑40144/40145 allow local privilege escalation and arbitrary code execution; the vendor advises upgrading to version 26.1.2 or monitoring kernel activity for mitigation.

    0000090
    510 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    BeyondTrust has patched two critical vulnerabilities in its Windows Endpoint Privilege Management (EPM) solution. CVE-2026-40144 and CVE-2026-40145 could allow local attackers to escalate privileges or bypass anti-tamper controls. Users should update to version 26.1.2 immediately to mitigate these risks. #CyberSecurity #BeyondTrust #EPM #Vulnerability #Windows #SecurityUpdate https://thedailytechfeed.com/beyondtrust-patches-critical-windows-epm-vulnerabilities/

    Post summary

    BeyondTrust has issued a patch for two critical Windows EPM vulnerabilities that could enable local privilege escalation; users are urged to upgrade to version 26.1.2 immediately.

    0000051
    651 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40144 A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to version 26.1.2. Insuff… https://www.cve.org/CVERecord?id=CVE-2026-40144 ----- Traducción: CVE-2026-40144 Exi… https://infoflow.cloud`

    Post summary

    The text announces CVE-2026-40144, describing a memory‑corruption flaw in BeyondTrust Endpoint Privilege Management affecting Windows deployments before version 26.1.2.

    0000026
    100 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40144 A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to version 26.1.2. Insuff… https://www.cve.org/CVERecord?id=CVE-2026-40144

    Post summary

    The text briefly discloses a memory‑corruption kernel-mode vulnerability in BeyondTrust Endpoint Privilege Management prior to version 26.1.2, with no mention of exploits, patches, or active exploitation.

    00000875
    58.0K followersView on X

Explore more