Microsoft · Windows · CVE-2026-26128
**Name of the Vulnerable Software and Affected Versions**
Windows 10 Version 1607
Windows Server 2025
Windows Server 2011
**Description**
Improper authentication in the Windows SMB Server allows an authorized attacker to elevate privileges locally. The issue involves a Kerberos reflection bypass, which can enable an attacker to gain SYSTEM privileges on most Windows builds. Approximately 756,600 instances were identified globally.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.