CVE-2026-42905
An attacker can exploit multiple vulnerabilities in various versions of Microsoft Windows and Microsoft Windows Server to gain administrative rights, execute arbitrary code, bypass security measures, manipulate and disclose data, or conduct spoofing attacks.
CSIRTS triage
- What
- Multiple vulnerabilities can be exploited to gain administrative rights and execute arbitrary code.
- Who is affected
- Various versions of Microsoft Windows and Windows Server are affected.
- Urgency
- Remediation is urgent due to the high severity and potential for significant impact.
- Action
- Install the latest security updates for Microsoft Windows.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-42905
Get an email if CVE-2026-42905 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Moderate exploitation risk2.0% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 79% of all EPSS-scored CVEs.
Advisory coverage (2)
- high[UPDATE] [high] Microsoft Windows: Multiple vulnerabilitiescert-bund · 2026-08-25
- highCVE-2026-42905: Windows DWM Core Library Elevation of Privilege Vulnerabilitymsrc · 2026-06-09
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-42905)