CVE-2026-40145Patch

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility and the agent's tamper protection controls. Under certain conditions, the protections applied to the utility process may not be enforced as intended.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1220

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-08-17); latest day: 1
  • 5 total mentions across 3 days

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-08-17: 2Mentions · 2026-08-19: 2Mentions · 2026-08-27: 1Patch / Workaround · 2026-08-19: 2Patch / Workaround · 2026-08-27: 1Technical Details · 2026-08-17: 1Technical Details · 2026-08-19: 2Technical Details · 2026-08-27: 108-1708-1908-27
Signal classification3 categories
Patch
360.0%
Disclosure
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-08-172
Disclosure1General1
2026-08-192
Patch2
2026-08-271
Patch1
Full discourse5 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    BeyondTrust patched two high-severity EPM flaws (CVE-2026-40144, CVE-2026-40145) allowing local privilege escalation on Windows. Update to 26.1.2. #BeyondTrust #CVE202640144 #PrivilegeEscalation #Windows #EndpointSecurity #InfoSec https://securityonline.info/beyondtrust-vulnerability-cve-2026-40144/

    Post summary

    The post announces that BeyondTrust has released a patch (26.1.2) for two high‑severity local privilege escalation flaws (CVE‑2026‑40144 and CVE‑2026‑40145) in its EPM product.

    01010417
    12.8K followersView on X
  • iototsecnews@iototsecnews
    Patch

    BeyondTrust Windows EPM の脆弱性 CVE-2026-40144/40145 が FIX:深刻な権限昇格の恐れ https://iototsecnews.jp/2026/08/19/beyondtrust-windows-epm-vulnerabilities-allows-attackers-to-escalate-privileges/ BeyondTrust Endpoint Privilege Management (Windows Deployment) における、特権制御処理に対する非検証の問題が生じています。この脆弱性 CVE-2026-40144/CVE-2026-40145 を悪用する攻撃者により、ローカル端末上での任意コード実行/改ざん防止機能の無効化/最上位権限の奪取といった重大な被害が生じる恐れがあります。対応策として、最新版 26.1.2 以降への更新/カーネル挙動の監視/不審な昇格アクティビティの検知が推奨されます。 #BeyondTrust #CVE202640144 #CVE202640145 #Vulnerability #WindowsEPM

    Post summary

    The article discloses CVE‑2026‑40144/40145 in BeyondTrust Windows Endpoint Privilege Management, details the privilege‑escalation threat, and advises updating to version 26.1.2 and monitoring for suspicious activity.

    0000090
    510 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    BeyondTrust has patched two critical vulnerabilities in its Windows Endpoint Privilege Management (EPM) solution. CVE-2026-40144 and CVE-2026-40145 could allow local attackers to escalate privileges or bypass anti-tamper controls. Users should update to version 26.1.2 immediately to mitigate these risks. #CyberSecurity #BeyondTrust #EPM #Vulnerability #Windows #SecurityUpdate https://thedailytechfeed.com/beyondtrust-patches-critical-windows-epm-vulnerabilities/

    Post summary

    The post announces that BeyondTrust patched two critical CVEs affecting its EPM component, warns of local privilege escalation risk, and urges users to upgrade to version 26.1.2 immediately.

    0000051
    651 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40145 A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility and the agent's tamper protection controls. Und… https://www.cve.org/CVERecord?id=CVE-2026-40145 ----- Traducción: CVE-2026-40145 Exi… https://infoflow.cloud`

    Post summary

    The text announces CVE‑2026‑40145, describing a vulnerability in the interaction between EP Management support utilities and tamper protection controls, but provides no PoC, exploit code, or mitigation details.

    0000020
    100 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-40145 A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility and the agent's tamper protection controls. Und… https://www.cve.org/CVERecord?id=CVE-2026-40145

    Post summary

    The message references CVE-2026-40145 with a brief statement about involved components, but it contains no PoC, exploit details, or mitigation information.

    00000893
    58.0K followersView on X

Explore more