CVE-2026-72966
Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.
CVSS
5.5
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-862
Not enough EPSS history yet.
Missing authorization in Windows Remote Access Connection Manager allows an authorized attacker to perform tampering locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-839427.8 HIG—
———Missing authorization in Windows Kernel allows an authorized attacker to elevate privileges locally.4hCVE-2026-839419.9 CRI—
———Missing authorization in Entra ID allows an authorized attacker to elevate privileges over a network.4hCVE-2026-818235.3 MED—
———The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are not impacted.4hCVE-2026-730147.8 HIG—
———Missing authorization in Data Sharing Service Client allows an authorized attacker to elevate privileges locally.4hCVE-2026-697248.8 HIG—
———Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.4hCVE-2026-696419.1 CRI—
———Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.4h