Critical Windows Kernel Vulnerability Enables SYSTEM Privilege Escalation
Article Content
- •CVE-2026-40369 allows unprivileged processes to escalate to SYSTEM privileges.
- •The vulnerability affects Windows 11 versions 24H2 through 25H2.
- •Exploitation can occur from browser sandboxes using a single API call.
A critical vulnerability in the Windows kernel, identified as CVE-2026-40369, has been disclosed, allowing unprivileged processes to escalate privileges to SYSTEM level. This flaw affects Windows 11 versions 24H2 through 25H2 and resides in the ntoskrnl.exe component, specifically within the ExpGetProcessInformation function. Attackers can exploit this vulnerability from restricted environments, such as browser sandboxes, using a single NtQuerySystemInformation call. The vulnerability was published on May 12, 2026, with a proof of concept (PoC) made public shortly after on May 14, 2026. Security researchers have emphasized the potential for widespread exploitation given the ease of access to the attack vector. Organizations using affected Windows versions are urged to apply security updates as soon as they are available.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-40369 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…