CVE-2026-40369Exploit(microsoft / windows_11_24h2)

CRITICALCVSS 7.8 · HIGH

Exploitation observed; activity peaked at 6 mentions and remains active

Immediate actions

  • Patch microsoft windows_11_24h2 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

9.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-822

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_11_24h2
  • windows_11_25h2
  • windows_11_26h1
  • windows_server_2025

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 51 mentions across 23 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 20 signals
  • PoC mentioned or linked in 32 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 41 signals
  • Disclosure: 14 classified signals
  • Peaked 20d ago at 6 mentions (2026-05-18); latest day: 1
  • 51 total mentions across 23 days

Affected systems

Vendors
Products
windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2025

Deep dive

Activity timeline51 mentions / 23d
02356Mentions · 2026-05-13: 2Mentions · 2026-05-17: 3Mentions · 2026-05-18: 6Mentions · 2026-05-19: 5Mentions · 2026-05-21: 4Mentions · 2026-05-22: 2Mentions · 2026-05-23: 1Mentions · 2026-05-24: 2Mentions · 2026-05-27: 6Mentions · 2026-05-30: 1Mentions · 2026-05-31: 1Mentions · 2026-06-01: 1Mentions · 2026-06-02: 2Mentions · 2026-06-03: 1Mentions · 2026-06-06: 1Mentions · 2026-06-10: 2Mentions · 2026-06-12: 1Mentions · 2026-06-13: 1Mentions · 2026-06-15: 1Mentions · 2026-06-17: 2Mentions · 2026-07-31: 2Mentions · 2026-08-20: 3Mentions · 2026-08-21: 1PoC Mentioned / Linked · 2026-05-13: 1PoC Mentioned / Linked · 2026-05-17: 3PoC Mentioned / Linked · 2026-05-18: 5PoC Mentioned / Linked · 2026-05-19: 4PoC Mentioned / Linked · 2026-05-21: 3PoC Mentioned / Linked · 2026-05-22: 2PoC Mentioned / Linked · 2026-05-23: 1PoC Mentioned / Linked · 2026-05-24: 2PoC Mentioned / Linked · 2026-05-27: 3PoC Mentioned / Linked · 2026-05-30: 1PoC Mentioned / Linked · 2026-06-01: 1PoC Mentioned / Linked · 2026-06-03: 1PoC Mentioned / Linked · 2026-06-06: 1PoC Mentioned / Linked · 2026-06-12: 1PoC Mentioned / Linked · 2026-06-17: 1PoC Mentioned / Linked · 2026-07-31: 1PoC Mentioned / Linked · 2026-08-20: 1Exploit Tool / Code · 2026-05-13: 1Exploit Tool / Code · 2026-05-17: 3Exploit Tool / Code · 2026-05-18: 4Exploit Tool / Code · 2026-05-19: 3Exploit Tool / Code · 2026-05-21: 2Exploit Tool / Code · 2026-05-22: 1Exploit Tool / Code · 2026-05-23: 1Exploit Tool / Code · 2026-05-24: 1Exploit Tool / Code · 2026-05-27: 1Exploit Tool / Code · 2026-06-12: 1Exploit Tool / Code · 2026-06-17: 1Exploit Tool / Code · 2026-08-20: 1Active Exploitation · 2026-05-27: 1Active Exploitation · 2026-06-02: 1Active Exploitation · 2026-06-06: 1Patch / Workaround · 2026-05-17: 1Patch / Workaround · 2026-05-18: 1Patch / Workaround · 2026-05-27: 1Patch / Workaround · 2026-08-20: 2Technical Details · 2026-05-13: 2Technical Details · 2026-05-17: 3Technical Details · 2026-05-18: 4Technical Details · 2026-05-19: 4Technical Details · 2026-05-21: 2Technical Details · 2026-05-22: 2Technical Details · 2026-05-23: 1Technical Details · 2026-05-24: 2Technical Details · 2026-05-27: 6Technical Details · 2026-05-30: 1Technical Details · 2026-06-01: 1Technical Details · 2026-06-03: 1Technical Details · 2026-06-06: 1Technical Details · 2026-06-10: 1Technical Details · 2026-06-12: 1Technical Details · 2026-06-13: 1Technical Details · 2026-06-15: 1Technical Details · 2026-06-17: 2Technical Details · 2026-07-31: 2Technical Details · 2026-08-20: 2Technical Details · 2026-08-21: 105-1305-1805-2105-2305-2705-3106-0206-0606-1206-1507-3108-21
Signal classification6 categories
Exploit
1529.4%
Disclosure
1427.5%
PoC
917.6%
General
815.7%
Active Exploitation
35.9%
Patch
23.9%
Referenced assets27 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-132
Disclosure1Exploit1
2026-05-173
Exploit2PoC1
2026-05-186
Disclosure1Exploit4PoC1
2026-05-195
Exploit2General1Patch1PoC1
2026-05-214
Disclosure1General2PoC1
2026-05-222
Disclosure1Exploit1
2026-05-231
Exploit1
2026-05-242
Exploit1PoC1
2026-05-276
Active Exploitation1Disclosure3Exploit1PoC1
2026-05-301
Disclosure1
2026-05-311
General1
2026-06-011
PoC1
2026-06-022
Active Exploitation1General1
2026-06-031
PoC1
2026-06-061
Active Exploitation1
2026-06-102
General2
2026-06-121
Exploit1
2026-06-131
Disclosure1
2026-06-151
General1
2026-06-172
Disclosure1PoC1
2026-07-312
Disclosure2
2026-08-203
Disclosure1Exploit1Patch1
2026-08-211
Disclosure1
Full discourse20 posts
  • Co11ateral@co11ateral
    Exploit

    CVE-2026-40369 A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browsers render process sandbox May has been too generous with all that.. Be careful and patch https://github.com/orinimron123/CVE-2026-40369-EXPLOIT #cybersecurity

    Post summary

    CVE-2026-40369 is a Windows kernel arbitrary write flaw enabling sandbox escape; a GitHub-hosted exploit appears available, and patching is advised.

    160025416815.5K
    8.9K followersView on X
  • 0xor0ne@0xor0ne
    Disclosure

    CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox https://voidsec.com/cve-2026-40369-browser-sandbox-escape/ #infosec https://t.co/nL5nTzNZqk

    Post summary

    The tweet announces the discovery of CVE‑2026‑40369, a browser sandbox escape vulnerability, and links to a VoidSec article that presumably contains technical details.

    031027915817.6K
    94.3K followersView on X
  • Paolo Stagno (VoidSec)@Void_Sec
    General

    I originally prepared this bug for Pwn2Own Berlin. A few days before the contest, a CVE got assigned. So, here is my technical analysis and exploitation strategy for CVE-2026-40369: a 12-byte kernel increment, exploitable both as an LPE and SBX. https://voidsec.com/cve-2026-40369-browser-sandbox-escape/

    Post summary

    The author shares a technical analysis and exploitation strategy for CVE‑2026‑40369, including kernel increment details and a link to VoidSec, but does not provide explicit PoC code or active exploitation evidence.

    16202108217.0K
    5.2K followersView on X
  • Dark Web Informer@DarkWebInformer
    Exploit

    ‼️ CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox. CVSS: 7.8 Writeup: https://voidsec.com/cve-2026-40369-browser-sandbox-escape/ PoC: https://github.com/orinimron123/CVE-2026-40369-EXPLOIT Credit: http://youtube.com/@VoidSec https://t.co/N6EwopDbR1

    Post summary

    This post announces CVE-2026-40369, a CVSS 7.8 browser sandbox escape, and supplies a PoC and exploit code, but does not discuss active exploitation or patches.

    22812199618.3K
    224.3K followersView on X
  • Clandestine@akaclandestine
    Exploit

    GitHub - orinimron123/CVE-2026-40369-EXPLOIT: Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browsers render process sandbox · GitHub https://github.com/orinimron123/CVE-2026-40369-EXPLOIT

    Post summary

    The post announces that full exploit code for CVE-2026-40369—a Windows kernel arbitrary write vulnerability that allows browser sandbox escape—is available on GitHub.

    143117811839.0K
    62.5K followersView on X
  • Ori Nimron@orinimron123
    PoC

    As promised - full blog post is live for CVE-2026-40369 Covers everything: initial research, methodology, the exploitation path, caveats, cleanups, etc. The whole journey from finding it to production-grade exploit: https://pwn2nimron.com/blog

    Post summary

    A blog post has been published detailing CVE‑2026‑40369, covering research, methodology, and a production‑grade exploit path; it confirms a PoC but provides no active exploitation data, patch info, or technical specifics.

    351116110419.2K
    488 followersView on X
  • Smukx.E@5mukx
    Disclosure

    CVE-2026-40369: Arbitrary Kernel Address Increment via NtQuerySystemInformation TL;dR: One syscall from any unprivileged process, even inside Chrome’s renderer sandbox, can increment arbitrary kernel memory addresses, giving SYSTEM privilege escalation https://pwn2nimron.com/blog https://t.co/WRck0kifCO

    Post summary

    The post discloses CVE‑2026‑40369, highlighting an arbitrary kernel address increment flaw that can be triggered by a single NtQuerySystemInformation call from any unprivileged process, accompanied by a link to a blog for further details.

    2380177939.7K
    24.3K followersView on X
  • SecureChap@SecureChap
    PoC

    cl /W4 /O2 poc.c /Fe:poc.exe /link ntdll.lib That single command builds a working exploit for CVE-2026-40369. The flaw sits in ntoskrnl.exe inside ExpGetProcessInformation. Info class 253 accepts a caller-supplied kernel address when the length argument is zero. Because the ProbeForWrite guard is wrapped inside an `if (Length)` check, a zero-length call skips validation entirely. The function then walks every process and executes three increments at the attacker-chosen address: `++*v95; v95[1] += threadCnt; v95[2] += handleCnt`. The primitive is deterministic and reachable from any sandbox that can still issue NtQuerySystemInformation, including Chrome, Edge, and Firefox renderers. It affects Windows 11 24H2 and 25H2. A crash lands as bugcheck 50 at nt!ExpGetProcessInformation+0x42e. Ori Nimron published the PoC at http://github.com/orinimron123/CVE-2026-40369-EXPLOIT. Combined with any KASLR leak the increment turns into a direct LPE. A length guard that only protects non-zero buffers leaves the kernel address exposed on every call.

    Post summary

    The message details a working PoC for CVE-2026-40369, including compilation steps, code link, and technical exploitation logic.

    141015510311.5K
    161 followersView on X
  • Nicolas Krassas@Dinosn
    Exploit

    Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browsers render process sandbox https://github.com/orinimron123/CVE-2026-40369-EXPLOIT

    Post summary

    The snippet shares a complete GitHub-hosted exploit for CVE-2026-40369, detailing a Windows kernel arbitrary write that can bypass browser sandboxes across all render processes.

    03801297812.1K
    158.6K followersView on X
  • yousukezan@yousukezan
    Exploit

    Windows 11最新環境で動作するカーネル権限昇格ゼロデイ「CVE-2026-40369」が公開された。NtQuerySystemInformationの欠陥を悪用し、Chromeサンドボックス内の低権限プロセスからでもカーネルメモリ書き換えが可能になる。 問題はntoskrnl.exe内のExpGetProcessInformationに存在し、SystemProcessInformationExtension(クラス253)処理時のNULLチェック欠如が原因だ。Length=0で呼び出すとProbeForWriteが完全に回避され、攻撃者が指定したカーネルアドレスへDWORD加算処理が実行される。これにより任意カーネルメモリのインクリメントが可能になり、権限昇格プリミティブとして悪用できる。 PoCではNtQuerySystemInformationへ細工したカーネルアドレスを渡し、プロセス数やスレッド数に応じた加算処理を実行する様子が示された。未マップ領域を指定した場合はBSODを引き起こすが、適切なアドレスを選べば安定動作するとされ、研究者は「100%決定論的」と主張している。 影響はWindows 11 24H2〜25H2で確認され、Chrome、Edge、Firefoxのサンドボックスからも到達可能とされる。KASLR回避には別ツールとの連携も提案されているが、現時点でMicrosoftから修正情報は出ていない。 https://github.com/orinimron123/CVE-2026-40369-EXPLOIT

    Post summary

    A kernel privilege‑escalation zero‑day (CVE‑2026‑40369) affecting Windows 11 24H2–25H2 is disclosed with a publicly available PoC/exploit repository, but no Microsoft patch has yet been released.

    0320110599.1K
    14.5K followersView on X
  • 0xor0ne@0xor0ne
    Disclosure

    Windows unprivileged arbitrary 12-byte kernel write to escape the browser sandbox https://voidsec.com/cve-2026-40369-browser-sandbox-escape/ #infosec

    Post summary

    The tweet announces CVE-2026-40369, a Windows kernel write‑vulnerability that allows sandbox escape, referencing an online article but offering no PoC, exploitation details, or patch information.

    123099595.6K
    92.6K followersView on X
  • dbugs@ptdbugs
    PoC

    Escaping the Browser Sandbox via the Windows Kernel Vulnerability CVE-2026-40369 PT ID: PT-2026-40204 The article examines the vulnerability CVE-2026-40369 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-40369), which enables a browser sandbox escape due to an error in handling a system call. The author shows how even a limited ability to write to kernel memory can be turned into a full exploitation primitive. The material подробно demonstrates the exploitation process, including gaining SYSTEM privileges and bypassing security mechanisms. Ultimately, the vulnerability allows an attacker to move from code execution inside the browser to full control over the operating system. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-40204 📎 Article: https://voidsec.com/cve-2026-40369-browser-sandbox-escape/ #dbugs_attacks

    Post summary

    The article presents a proof‑of‑concept that illustrates how CVE‑2026‑40369 allows a browser sandbox escape to gain kernel‑level SYSTEM privileges, detailing the exploitation flow.

    017066253.3K
    2.6K followersView on X
  • Ori Nimron@orinimron123
    Exploit

    @M4x_1997 4/4: Last but not least CVE-2026-40369 - Windows Kernel Arbitrary Increment primitive reachable from any browser sandbox renderer process This one was rejected from Pwn2Own and closed anyway yesterday :( My exploit is here - blogpost will be soon: https://github.com/orinimron123/CVE-2026-40369-EXPLOIT https://t.co/nG8vwixZO2

    Post summary

    The author confirms a Windows kernel vulnerability (CVE‑2026‑40369) with an arbitrary increment primitive and releases exploit code on GitHub; there is no evidence of active exploitation or patches.

    3201512523.4K
    488 followersView on X
  • Crowdfense@crowdfense
    General

    Technical analysis and exploitation strategy for CVE-2026-40369: a 12-byte kernel increment exploitable both as LPE and SBX. Originally prepared for Pwn2Own Berlin, the bug became public shortly before the contest after CVE assignment. https://voidsec.com/cve-2026-40369-browser-sandbox-escape/

    Post summary

    The entry briefly outlines the technical nature of CVE‑2026‑40369 and its exposure before a Pwn2Own event but provides no explicit proof‑of‑concept, exploit code, or patch information.

    011048253.4K
    3.0K followersView on X
  • hackyboiz@hackyboiz2
    Disclosure

    [1day-1line] CVE-2026-40369: Arbitrary Kernel Address Increment LPE/Sandbox Escape Vulnerability Caused by Untrusted Pointer Dereference in Windows Kernel(ntoskrnl.exe) Hello, this is banda. Today's 1day-1line covers an LPE/Sandbox Escape vulnerability in the Windows Kernel. In the NtQuerySystemInformation Class 253 path, Length=0 can bypass pointer validation and trigger a limited 12-byte kernel write primitive at an attacker-controlled kernel address, potentially leading to SYSTEM privilege escalation even from restricted environments such as a browser renderer sandbox. Please refer to the blog post for more details! https://hackyboiz.github.io/2026/06/17/banda/CVE-2026-40369/

    Post summary

    This post announces a new Windows kernel LPE/Sandbox escape via NtQuerySystemInformation, providing technical details but no proof‑of‑concept, exploit tool, patch, or evidence of active exploitation.

    09036162.8K
    525 followersView on X
  • Clandestine@akaclandestine
    PoC

    CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox https://core-jmp.org/2026/06/cve-2026-40369-twelve-bytes-browser-sandbox-escape/

    Post summary

    The linked article presents CVE‑2026‑40369, describing a sandbox‑escape flaw and providing a minimal proof‑of‑concept but does not mention active attacks or available patches.

    010028173.0K
    63.3K followersView on X
  • Dark Web Intelligence@DailyDarkWeb
    General

    🚨 Windows 11 Local Privilege Escalation Exploit Advertised on Underground Forum A threat actor is advertising a ready-to-use Local Privilege Escalation (LPE) exploit allegedly targeting Windows 11 24H2 and 25H2 systems. * The seller claims the exploit weaponizes CVE-2026-40369 and is being offered for $10,000. * According to the advertisement, the exploit allegedly: * Supports multiple Windows builds without modification * Achieves SYSTEM-level privileges * Avoids common process injection techniques * Claims low detection rates by endpoint security products * Works more reliably on Intel processors than AMD systems * Has limited effectiveness in virtualized environments * The actor further claims the exploit requires access to ntoskrnl.exe memory layout information and relies on kernel-level behavior to achieve privilege escalation. * No proof-of-concept, demonstration video, or independent validation was publicly provided in the listing. * At the time of reporting, Daily Dark Web could not independently verify the authenticity, reliability, or exclusivity of the advertised exploit. Analyst Note: Functional Windows LPE exploits remain highly valuable in cybercriminal and nation-state operations because they are frequently chained with phishing, malware, browser exploits, or initial access brokers to obtain SYSTEM privileges and disable security controls. Organizations should prioritize June Patch Tuesday updates, monitor for abnormal privilege escalation activity, and treat public exploit-sale claims with caution until technical validation becomes available. #DDW #Intelligence #DarkWeb #Windows

    Post summary

    An underground forum advertises a ready‑to‑use Windows 11 LPE exploit for CVE‑2026‑40369, but no proof‑of‑concept, exploit code, or evidence of active exploitation is provided, warranting caution until verification.

    1101452.5K
    196.7K followersView on X
  • Soufiane@S0ufi4n3
    Exploit

    Full exploit code for CVE-2026-40369 - A Windows kernel arbitrary write vulnerability that allows browser sandbox escape from all browsers render process sandbox https://github.com/orinimron123/CVE-2026-40369-EXPLOIT

    Post summary

    The message presents a complete exploit for CVE-2026-40369, linking to GitHub code and detailing it as a Windows kernel arbitrary write that escapes browser sandbox.

    03097954
    14.4K followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #Kernel_Security CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox https://voidsec.com/cve-2026-40369-browser-sandbox-escape ]-> Full Exploit PoC - https://github.com/orinimron123/CVE-2026-40369-EXPLOIT // Windows kernel vulnerability enabling unprivileged arbitrary kernel memory writes via 'NtQuerySystemInformation', allowing privilege escalation to SYSTEM by forging tokens, affecting Windows 11 25H2 and Windows Server 2025

    Post summary

    The post announces a full exploit for CVE-2026-40369, which allows unprivileged users to perform arbitrary kernel memory writes and privilege escalation on Windows 11 25H2 and Windows Server 2025.

    060531.3K
    3.3K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox https://voidsec.com/cve-2026-40369-browser-sandbox-escape/

    Post summary

    The post announces CVE-2026-40369, a browser sandbox escape vulnerability dubbed ‘Twelve Bytes,’ and shares a PoC, but provides no patch, active‑exploitation data, or technical depth.

    020551.3K
    158.6K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2025---

Explore more