CVE-2026-66799
published 2026-08-11CVE-2026-66799: Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.
PriorityP349high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
19.4th percentile
Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1607 | < 10.0.14393.9418 | 10.0.14393.9418 |
| microsoft | windows_10_1809 | < 10.0.17763.9115 | 10.0.17763.9115 |
| microsoft | windows_10_21h2 | < 10.0.19044.7663 | 10.0.19044.7663 |
| microsoft | windows_10_22h2 | < 10.0.19045.7663 | 10.0.19045.7663 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.9418 | 10.0.14393.9418 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.9121 | 10.0.17763.9121 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.7663 | 10.0.19044.7663 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.7663 | 10.0.19045.7663 |
| microsoft | windows_11_23h2 | < 10.0.22631.7517 | 10.0.22631.7517 |
| microsoft | windows_11_24h2 | < 10.0.26100.9106 | 10.0.26100.9106 |
| microsoft | windows_11_25h2 | < 10.0.26200.9106 | 10.0.26200.9106 |
| microsoft | windows_11_26h1 | < 10.0.28000.2704 | 10.0.28000.2704 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.7517 | 10.0.22631.7517 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.9168 | 10.0.26100.9168 |
| microsoft | windows_11_version_25h2 | >= 10.0.26200.0 < 10.0.26200.9168 | 10.0.26200.9168 |
| microsoft | windows_11_version_26h1 | >= 10.0.28000.0 < 10.0.28000.2704 | 10.0.28000.2704 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.26280 | 6.2.9200.26280 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.23338 | 6.3.9600.23338 |
| microsoft | windows_server_2016 | < 10.0.14393.9418 | 10.0.14393.9418 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.9418 | 10.0.14393.9418 |
| microsoft | windows_server_2019 | < 10.0.17763.9115 | 10.0.17763.9115 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.9121 | 10.0.17763.9121 |
| microsoft | windows_server_2022 | < 10.0.20348.5440 | 10.0.20348.5440 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.5499 | 10.0.20348.5499 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Microsoft Windows up to Server 2025 Key Guard buffer overflow
vuldb·2026-08-12·CVSS 7.8
CVE-2026-66799 [HIGH] Microsoft Windows up to Server 2025 Key Guard buffer overflow
A vulnerability marked as very critical has been reported in Microsoft Windows. This affects an unknown function of the component Key Guard. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2026-66799. Local access is required to approach this attack. No exploit exists.
It is recommended to apply a patch to fix this issue.
GHSA
Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.
ghsa_unreviewed·2026-08-11
CVE-2026-66799 [HIGH] CWE-122 Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.
Heap-based buffer overflow in Windows Key Guard allows an authorized attacker to elevate privileges locally.
Red Hat
cluster-backup-operator: cluster-backup-operator: Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement
vendor_redhat·2026-08-11·CVSS 7.8
CVE-2026-66799 [HIGH] CWE-863 cluster-backup-operator: cluster-backup-operator: Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement
cluster-backup-operator: cluster-backup-operator: Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement
A flaw was found in the cluster-backup-operator. A privileged user with administrative access to a specific namespace could exploit a vulnerability in the backup restoration process. This flaw allows them to redirect sensitive information, such as cloud provider credentials and access tokens, from backup operations into other namespaces, including those they control. This could lead to unauthorized access to critical system resources and the disclosure of confidential data.
Statement: This is an Important vulnerability in Red Hat Advanced Cluster Management for Kubernetes. A namespace administrator within the `open-cluster-management-backup` name
No detection rules found.
No public exploits indexed.
Rapid7
Patch Tuesday - August 2026
blogs_rapid7·2026-08-11·CVSS 7.2
CVE-2026-68821 [HIGH] Patch Tuesday - August 2026
Microsoft is publishing 421 vulnerabilities on August 2026 Patch Tuesday , including 236 vulnerabilities in Windows. This is lower volume than last month’s record-breaking behemoth, but still one of the largest Patch Tuesday totals ever. There is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for one of the vulnerabilities published today, as well as public disclosure for two others, although the Notable CVEs section of the Security Update Guide omits one of these. As usual, browser vulns are not included in the Patch Tuesday count above, but unusually, Microsoft does not appear to have published any desktop browser security patches so far this month.
## Summary charts
## Summary tables
#
Qualys
Microsoft Patch Tuesday, August 2026 Security Update Review
blogs_qualys·2026-08-11
CVE-2026-72971 Microsoft Patch Tuesday, August 2026 Security Update Review
## Table of Contents
Microsoft Patch Tuesday forAugust2026
Zero-day Vulnerabilities Patched inAugustPatch Tuesday Edition
Critical Severity Vulnerabilities Patched inAugustPatch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Qualys Monthly Webinar Series
The August 2026 Microsoft Patch Tuesday release delivers security fixes for vulnerabilities affecting a wide range of Microsoft products and services. As attackers continue to exploit unpatched vulnerabilities, timely patching remains critical for reducing exposure and strengthening enterprise security.
## Microsoft Patch Tuesday for August 2026
This month’s release addresses 421 vulnerabilities, including 62 critical and 357 important-severity vulnerabilities.
In this month’s updates, Microsof
Sans Isc
Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
blogs_sans_isc·2026-08-11·CVSS 7.8
CVE-2026-68820 [HIGH] Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
Microsoft Patch Tuesday August 2026
Published: 2026-08-11. Last Updated: 2026-08-11 17:54:49 UTC
by Renato Marinho (Version: 1)
0 comment(s)
This month we got patches for 418 vulnerabilities. Of these, 62 are critical, 1 is being exploited in the wild, and 2 were publicly disclosed as zero-days. Notable fixes include Windows privilege escalation, container tampering, and critical QUIC and DNS Server remote code execution bugs.
A few vulnerabilities worth mentioning:
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability (CVE-2026-68820)
This Important-severity elevation of privilege vulnerability is listed by Microsoft as exploited in the wild but not publicly disclosed, and it has a CVSS score of 7.0. The flaw is a use-after-free issue in the Windows Ancil
Talos
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
blogs_talos·2026-08-11·CVSS 9.4
CVE-2026-68820 [CRITICAL] Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for August 2026, which includes 421 vulnerabilities affecting a range of products, including 62 that Microsoft marked as "critical."
Microsoft notes that 1 of the vulnerabilities disclosed this month have been exploited in the wild
CVE-2026-68820 is an elevation of privilege vulnerability affecting Windows Ancillary Function Driver for WinSock. A Use After Free vulnerability could allow an authorized attacker to elevate privileges locally. This vulnerability has a CVSS base score of 7.0.
Out of 62 "critical" vulnerabilities, 40 are remote code execution (RCE) vulnerabilities.
Microsoft considers exploitation of the following vulnerabilities more lik
Crowdstrike
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs
blogs_crowdstrike
CVE-2026-68820 August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs Aug 11, 2026
CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX Aug 07, 2026
Expanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery Aug 06, 2026
Secure Agent Harness Execution: Preventing Escape Aug 04, 2026
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs Aug 11, 2026
CrowdStrike Threat Hunts for Shell Command Obfuscation on VMware ESX Aug 07, 2026
Expanding AI Benchmarks in Cybersecurity Beyond Vulnerability Discovery Aug 06, 2026
Secure Agent Harness Execution: Preventing Escape Aug 04, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders
Bugzilla
CVE-2026-66799 cluster-backup-operator: cluster-backup-operator: Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement
bugzilla·2026-07-28·CVSS 7.8
CVE-2026-66799 [HIGH] CVE-2026-66799 cluster-backup-operator: cluster-backup-operator: Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement
CVE-2026-66799 cluster-backup-operator: cluster-backup-operator: Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement
The cluster-backup-operator passes Restore.spec.namespaceMapping verbatim into the Velero Restore object (controllers/restore.go:878-880) with no restriction on target namespaces. The same function hardcodes ExistingResourcePolicy=update (line 856), so name-colliding resources in the mapped target namespace are overwritten.
The credentials backup (controllers/backup.go:123-126) contains Secret and ConfigMap objects from ACM/Hive-labelled namespaces including cloud-provider credentials, pull secrets, and ManagedServiceAccount tokens. A namespace-admin in open-cluster-management-backup can create a Restore CR with a namespaceMapping
2026-08-11
Published