Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2976 articles · 110847 vulns · 36/41 feeds (7d)
← Back to list
8.7
CVE-2026-27928PATCHED
Microsoft · Windows Server 2016

Windows Hello Security Feature Bypass Vulnerability

Description

Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security feature over a network.

Affected Products

VendorProductVersions
MicrosoftWindows Server 201610.0.14393.0, 10.0.14393.0, 10.0.17763.0, 10.0.17763.0, 10.0.20348.0, 10.0.25398.0, 10.0.26100.0, 10.0.26100.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftwindows server 2016 (server core installation)mitre_affected90%
microsoftwindows server 2022, 23h2 edition (server core installation)mitre_affected90%
microsoftwindows server 2019 (server core installation)mitre_affected90%
microsoftwindows server 2025 (server core installation)mitre_affected90%
microsoftwindowsmitre_affected90%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-27928(vendor-advisory, patch)

Related News (2 articles)

Tier C
VulDB5h ago
CVE-2026-27928 | Microsoft Windows input validation
→ No new info (linked only)
Tier A
Microsoft MSRC9h ago
CVE-2026-27928 Windows Hello Security Feature Bypass Vulnerability
→ No new info (linked only)
CVSS 3.18.7 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N/E:U/RL:O/RC:C
CISA KEV❌ No
Actively exploited❌ No
Patch available
10.0.14393.906010.0.17763.864410.0.20348.502010.0.25398.227410.0.26100.32690
CWECWE-20
PublishedApr 14, 2026
Last enriched5h agov2
Tags
CVE-2026-27928
Trending Score43
Source articles2
Independent2
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-32201EXPKEV
Microsoft SharePoint Server Spoofing Vulnerability
Trending: 151
HIGHCVE-2026-26171EXP
.NET Denial of Service Vulnerability
Trending: 71
HIGHCVE-2026-32071EXP
Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
Trending: 67
HIGHCVE-2026-32093EXP
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
Trending: 67
HIGHCVE-2026-32075EXP
Windows UPnP Device Host Elevation of Privilege Vulnerability
Trending: 67

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 14, 2026
Discovered by ZDM
Apr 14, 2026
Updated: affectedVersions, tags
Apr 14, 2026
Patch Available
Apr 14, 2026

Version History

v2
Last enriched 5h ago
v2Tier C5h ago

Updated severity to CRITICAL, added new affected versions, and marked the vulnerability as actively exploited.

affectedVersionstags
via VulDB
v15h ago

Initial creation