Use-after-free in Microsoft Windows and Windows Server - CVE-2026-65776
Published: August 12, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to use-after-free in Windows Win32K when handling crafted local operations. A local user can trigger a race condition to escalate privileges.
Successful exploitation requires winning a race condition. An attacker who successfully exploits the issue could gain SYSTEM privileges.
Affected software
Windows Server
How to mitigate CVE-2026-65776
Windows Server - addressed in versions 2025 10.0.26100.33222, 2025 10.0.26100.33296