ThreatCluster

HardBreacher Claims Zero-Day in Kaspersky Endpoint Security

First seen 31 Aug 2026, 21:35 UTC GbhackersCybersecuritynews 52

Article Content

Browse articles
ThreatCluster

A proof of concept (PoC) named HardBreacher has been published, claiming a local privilege escalation vulnerability in Kaspersky Endpoint Security on fully patched Windows 11 systems. The flaw, described as a zero-day vulnerability, allows local users to gain control over privileged components. The researcher MSNightmare released the PoC, but Kaspersky has not confirmed the issue or assigned a CVE. As of now, the vulnerability remains unverified and lacks an official patch. The potential impact could affect numerous organizations using Kaspersky Endpoint Security, but the exact scope is unknown. No active exploitation has been reported yet, but the situation warrants monitoring. Security professionals are advised to stay alert for updates from Kaspersky regarding this claim.

Key Points: • HardBreacher claims a zero-day vulnerability in Kaspersky Endpoint Security. • The flaw allows local privilege escalation on Windows 11 systems. • Kaspersky has not confirmed the vulnerability or issued a CVE.

Timeline

2026-08-31
HardBreacher PoC published
A researcher named MSNightmare released a PoC claiming a local privilege escalation flaw in Kaspersky Endpoint Security.
Cybersecuritynews
2026-08-31
Gbhackers reports on HardBreacher
Gbhackers published an article detailing the HardBreacher exploit targeting Kaspersky Antivirus for Endpoint, highlighting the lack of vendor confirmation.
Gbhackers