Security Feature Bypass in Windows Hello by Microsoft
CVE-2026-27928
8.7HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 14 April 2026
What is CVE-2026-27928?
A security feature bypass vulnerability exists in Windows Hello due to improper input validation. This flaw permits unauthorized attackers to exploit the system over a network, effectively circumventing intended security measures. Users are encouraged to apply the relevant patches to mitigate the risk associated with this vulnerability.
Affected Version(s)
Windows Server 2016 (Server Core installation) x64-based Systems 10.0.14393.0 < 10.0.14393.9060
Windows Server 2016 x64-based Systems 10.0.14393.0 < 10.0.14393.9060
Windows Server 2019 (Server Core installation) x64-based Systems 10.0.17763.0 < 10.0.17763.8644