CVE-2026-85921
HIGHCVE-2026-85921 Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Description
Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
CVSS Scores
EPSS Score
Higher than 18% of all CVEs
Exploit maturity
Disclosed — This vulnerability has been publicly disclosed but no exploit code has been observed yet.
- No vendor patch available yet.
Exploitation probability (EPSS)
EPSS exploitation probability: 0.3%. This vulnerability ranks in the top 82% of all CVEs by exploitation likelihood. Last updated on Sep 15, 2026.
Attack surface
This vulnerability is requires local access to exploit. low complexity. high privileges required. no user interaction needed. impact extends beyond the vulnerable component.
Other vulnerabilities affecting Microsoft Security Response Center
CVE-2026-85892 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Sep 11, 2026
CVE-2026-77490 Microsoft Edge (Chromium-based) Spoofing Vulnerability
Sep 11, 2026
Chromium: CVE-2025-2137 Out of bounds read in V8
Sep 11, 2026
Chromium: CVE-2025-1920 Type Confusion in V8
Sep 11, 2026
CVE-2026-87658: Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain cross-origin ...
Sep 9, 2026
CVE-2026-87657: Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory inside ...
Sep 9, 2026
Primary source
Original advisory or reference for this vulnerability (via https://api.msrc.microsoft.com/update-guide/rss).
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921