SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-72966

MEDIUM · CVSS 5.5 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Windows Remote Access Connection Manager is vulnerable due to missing authorization, enabling an authorized attacker to manipulate settings locally. This could lead to unauthorized access or disruption of remote connections, potentially compromising system integrity. Organizations using Windows should prioritize this vulnerability, especially those with remote access capabilities, to mitigate risks associated with local tampering.

CVE
CVE-2026-72966
Severity
MEDIUM
CVSS
5.5
EPSS
0.29%
Windows

Original NVD Description

Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.