Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2977 articles · 110847 vulns · 36/41 feeds (7d)
← Back to list
7.5
CVE-2026-32071EXPLOITEDPATCHED
Microsoft · Windows 10 Version 1607

Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability

Description

Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an unauthorized attacker to deny service over a network.

Affected Products

VendorProductVersions
MicrosoftWindows 10 Version 160710.0.14393.0, 10.0.17763.0, 10.0.19044.0, 10.0.19045.0, 10.0.22631.0, 10.0.22631.0, 10.0.26100.0, 10.0.26200.0, 10.0.28000.0, 10.0.14393.0, 10.0.14393.0, 10.0.17763.0, 10.0.17763.0, 10.0.20348.0, 10.0.25398.0, 10.0.26100.0, 10.0.26100.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftwindows 10 versionmitre_affected90%
microsoftwindows 11 version 22h3mitre_affected90%
microsoftwindows 11 version 26h1mitre_affected90%
microsoftwindowsmitre_affected90%
microsoftwindows server 2016 (server core installation)mitre_affected90%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-32071(vendor-advisory, patch)

Related News (2 articles)

Tier C
VulDB4h ago
CVE-2026-32071 | Microsoft Windows up to Server 2025 Local Security Authority Subsystem Service null pointer dereference
→ No new info (linked only)
Tier A
Microsoft MSRC8h ago
CVE-2026-32071 Windows Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
10.0.14393.906010.0.17763.864410.0.19044.718410.0.19045.718410.0.22631.693610.0.26100.3269010.0.26200.824610.0.28000.183610.0.20348.502010.0.25398.2274
CWECWE-476
PublishedApr 14, 2026
Last enriched4h agov3
Tags
CVE-2026-32071
Trending Score67
Source articles2
Independent2
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-32201EXPKEV
Microsoft SharePoint Server Spoofing Vulnerability
Trending: 151
HIGHCVE-2026-26171EXP
.NET Denial of Service Vulnerability
Trending: 71
HIGHCVE-2026-32093EXP
Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability
Trending: 67
HIGHCVE-2026-32075EXP
Windows UPnP Device Host Elevation of Privilege Vulnerability
Trending: 67
HIGHCVE-2026-26154EXP
Windows Server Update Service (WSUS) Tampering Vulnerability
Trending: 67

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 14, 2026
Discovered by ZDM
Apr 14, 2026
Updated: description, exploitAvailable, activelyExploited
Apr 14, 2026
Updated: tags
Apr 14, 2026
Actively Exploited
Apr 14, 2026
Exploit Available
Apr 14, 2026
Patch Available
Apr 14, 2026

Version History

v3
Last enriched 4h ago
v3Tier C4h ago

Updated severity to CRITICAL, noted no exploit exists, and added new CVE ID tag.

tags
via VulDB
v2Tier A5h ago

Added a detailed description of the vulnerability and marked it as actively exploited with an exploit available.

descriptionexploitAvailableactivelyExploited
via Microsoft MSRC
v15h ago

Initial creation