Aug 2026: Active Directory Security Feature Bypass Vulnerability
CVE-2026-65777 Published on August 11, 2026

Active Directory Security Feature Bypass Vulnerability
Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature over a network.

Vendor Advisory NVD

Weakness Type

Inadequate Encryption Strength

The software stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required. A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.


Products Associated with CVE-2026-65777

Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.

 
 
 
 
 
 

Affected Versions

Microsoft Windows 11 version 23H2: Microsoft Windows 11 Version 23H2: Microsoft Windows 11 Version 24H2: Microsoft Windows 11 Version 25H2: Microsoft Windows 11 version 26H1: Microsoft Windows Server 2022: Microsoft Windows Server 2025: Microsoft Windows Server 2025 (Server Core installation):