SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-72954

HIGH · CVSS 7.5 EPSS 0.60%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in Windows Deployment Services allows an authenticated attacker to execute arbitrary code remotely over a network. This high-severity flaw poses a significant risk to organizations utilizing Windows for deployment services, particularly those with exposed network configurations. IT and security teams should prioritize patching this vulnerability to mitigate potential exploitation.

CVE
CVE-2026-72954
Severity
HIGH
CVSS
7.5
EPSS
0.60%
Windows

Original NVD Description

Use after free in Windows Deployment Services allows an authorized attacker to execute code over a network.