SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-72980

MEDIUM · CVSS 4.4 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An uncontrolled search path vulnerability in Windows Hello allows an authorized attacker to bypass security features locally, potentially compromising user authentication. This issue primarily affects Windows systems and could lead to unauthorized access to sensitive information or system functions. Organizations using Windows Hello should prioritize addressing this vulnerability to maintain the integrity of their authentication processes.

CVE
CVE-2026-72980
Severity
MEDIUM
CVSS
4.4
EPSS
0.31%
Windows

Original NVD Description

Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.