SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-69395

MEDIUM · CVSS 6.5 EPSS 0.88%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Active Directory Certificate Services (AD CS) is vulnerable due to the use of externally-controlled format strings, enabling authorized attackers to potentially disclose sensitive information over the network. Organizations utilizing AD CS should prioritize addressing this vulnerability to mitigate the risk of information leakage. This is particularly critical for environments where sensitive data is handled or where compliance with security standards is required.

CVE
CVE-2026-69395
Severity
MEDIUM
CVSS
6.5
EPSS
0.88%

Original NVD Description

Use of externally-controlled format string in Active Directory Certificate Services (AD CS) allows an authorized attacker to disclose information over a network.