Critical Race Condition Vulnerabilities in Windows Bluetooth and Kerberos

Critical Race Condition Vulnerabilities in Windows Bluetooth and Kerberos

First seen 10 Mar 2026, 17:28 UTC Api.Msrc.Microsoft 70.5

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities (CVE-2026) have been identified in Windows systems, affecting both the Bluetooth RFCOM Protocol Driver and the Kerberos authentication protocol. The Bluetooth vulnerability allows authorized attackers to elevate privileges locally, while the Kerberos flaw enables unauthorized attackers to bypass security features over a network. Both vulnerabilities stem from improper synchronization in concurrent execution.

Timeline

2026-03-10
CVE-2026 published with details on Bluetooth and Kerberos vulnerabilities