CVE-2026-65777: Active Directory Security Feature Bypass Vulnerability

Overview

Severity
Medium (CVSS 5.3)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
Category
Security Feature Bypass
Exploit Status
Not Exploited
Exploitation Likelihood
Unlikely
Patch Tuesday
2026-Aug
Released
2026-08-11

Description

Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.

FAQ

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to have a deep understanding of the system and the ability to manipulate its components to trigger a specific condition. Successful exploitation is not guaranteed and depends on a combination of factors that may include the environment, system configuration, and the presence of additional security measures. What security feature could an attacker bypass by exploiting this vulnerability? An attacker who successfully exploited this vulnerability could bypass a cryptographic key validation policy, causing a key that should have been rejected as weak to be accepted.

Affected Products (12)

Windows

  • Windows Server 2022
  • Windows Server 2022 (Server Core installation)
  • Windows Server 2025 (Server Core installation)
  • Windows 11 Version 25H2 for ARM64-based Systems
  • Windows 11 Version 25H2 for x64-based Systems
  • Windows 11 Version 23H2 for ARM64-based Systems
  • Windows 11 Version 23H2 for x64-based Systems
  • Windows 11 Version 24H2 for ARM64-based Systems
  • Windows 11 Version 24H2 for x64-based Systems
  • Windows Server 2025
  • Windows 11 version 26H1 for x64-based Systems
  • Windows 11 Version 26H1 for ARM64-based Systems

Security Updates (8)

Acknowledgments

Anonymous

Revision History

  • 2026-08-11: Information published.