CVE-2026-65784
published 2026-08-11CVE-2026-65784: Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
PriorityP427medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.30%
22.4th percentile
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1607 | < 10.0.14393.9418 | 10.0.14393.9418 |
| microsoft | windows_10_1809 | < 10.0.17763.9115 | 10.0.17763.9115 |
| microsoft | windows_10_21h2 | < 10.0.19044.7663 | 10.0.19044.7663 |
| microsoft | windows_10_22h2 | < 10.0.19045.7663 | 10.0.19045.7663 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.9418 | 10.0.14393.9418 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.9121 | 10.0.17763.9121 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.7663 | 10.0.19044.7663 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.7663 | 10.0.19045.7663 |
| microsoft | windows_11_23h2 | < 10.0.22631.7517 | 10.0.22631.7517 |
| microsoft | windows_11_24h2 | < 10.0.26100.9106 | 10.0.26100.9106 |
| microsoft | windows_11_25h2 | < 10.0.26200.9106 | 10.0.26200.9106 |
| microsoft | windows_11_26h1 | < 10.0.28000.2704 | 10.0.28000.2704 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.7517 | 10.0.22631.7517 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.9168 | 10.0.26100.9168 |
| microsoft | windows_11_version_25h2 | >= 10.0.26200.0 < 10.0.26200.9168 | 10.0.26200.9168 |
| microsoft | windows_11_version_26h1 | >= 10.0.28000.0 < 10.0.28000.2704 | 10.0.28000.2704 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.26280 | 6.2.9200.26280 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.23338 | 6.3.9600.23338 |
| microsoft | windows_server_2016 | < 10.0.14393.9418 | 10.0.14393.9418 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.9418 | 10.0.14393.9418 |
| microsoft | windows_server_2019 | < 10.0.17763.9115 | 10.0.17763.9115 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.9121 | 10.0.17763.9121 |
| microsoft | windows_server_2022 | < 10.0.20348.5440 | 10.0.20348.5440 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.5499 | 10.0.20348.5499 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Windows up to Server 2025 NTFS out-of-bounds
vuldb·2026-08-12·CVSS 5.5
CVE-2026-65784 [MEDIUM] Microsoft Windows up to Server 2025 NTFS out-of-bounds
A vulnerability classified as problematic was found in Microsoft Windows. Impacted is an unknown function of the component NTFS. Executing a manipulation can lead to out-of-bounds read.
This vulnerability is tracked as CVE-2026-65784. The attack is restricted to local execution. No exploit exists.
It is best practice to apply a patch to resolve this issue.
GHSA
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
ghsa_unreviewed·2026-08-11
CVE-2026-65784 [MEDIUM] CWE-125 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information locally.
No detection rules found.
No public exploits indexed.
Rapid7
Patch Tuesday - August 2026
blogs_rapid7·2026-08-11·CVSS 7.2
CVE-2026-68821 [HIGH] Patch Tuesday - August 2026
Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the Notable CVEs section of the Security Update Guide omits one of these. As usual, browser vulns are not included in the Patch Tuesday count above, but unusually, Microsoft does not appear to have published any desktop browser security patches so far this month.
## Summary charts
## Summary tables
#
Sans Isc
Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
blogs_sans_isc·2026-08-11·CVSS 7.8
CVE-2026-68820 [HIGH] Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
Microsoft Patch Tuesday August 2026
Published: 2026-08-11. Last Updated: 2026-08-11 17:54:49 UTC
by Renato Marinho (Version: 1)
0 comment(s)
This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execution bugs.
A few vulnerabilities worth mentioning:
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820)
This Important-severity elevation of privilege vulnerability is listed by Microsoft as exploited in the wild but not publicly disclosed, and it has a CVSS score of 7.0. The flaw is a use-after-free issue in the Windows Ancil
Wiz
CVE-2025-65784 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.5
CVE-2025-65784 [MEDIUM] CVE-2025-65784 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-65784 :
NixOS vulnerability analysis and mitigation
Insecure permissions in Hubert Imoveis e Administracao Ltda Hub v2.0 1.27.3 allows authenticated attackers with low-level privileges to access other users' information via a crafted API request.
Source : NVD
## 6.5
Score
Published January 13, 2026
Severity MEDIUM
CNA Score 6.5
Affected Technologies
NixOS
Homebrew
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 9.3
Exploitation Probability (EPSS) N/A
Affected packages and libraries
hub
Sources
NVD
Homebrew Severity MEDIUM No Fix Added at: Feb 15, 2026
Nix Severity MEDIUM No Fix Added at: Feb 15, 2026
## Get a CVE risk assessment
Get a prioritized view of CVEs i
2026-08-11
Published