CVE-2026-85921

HIGH
Source

CVE-2026-85921 Windows Secure Kernel Mode Elevation of Privilege Vulnerability

Microsoft Security Response CenterPublished Sep 14, 2026Modified 1d agohttps://api.msrc.microsoft.com/update-guide/rssMaturity: disclosed

Description

Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVSS Scores

8.2
Base Score
Exploitability1.5
Impact6.0

EPSS Score

EPSS Probability0.26%

Higher than 18% of all CVEs

Exploit maturity

DisclosedThis vulnerability has been publicly disclosed but no exploit code has been observed yet.

  • No vendor patch available yet.

Exploitation probability (EPSS)

EPSS exploitation probability: 0.3%. This vulnerability ranks in the top 82% of all CVEs by exploitation likelihood. Last updated on Sep 15, 2026.

Attack surface

This vulnerability is requires local access to exploit. low complexity. high privileges required. no user interaction needed. impact extends beyond the vulnerable component.

Other vulnerabilities affecting Microsoft Security Response Center

Primary source

Original advisory or reference for this vulnerability (via https://api.msrc.microsoft.com/update-guide/rss).

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921