July 8, 2026
- Synacktiv publicly disclosed a Kerberos reflection bypass, CVE-2026-26128, with working PoC code that gives a domain user SYSTEM on most Windows builds. This is a straightforward local privilege escalation from any authenticated user, so patch prioritization is warranted. securityonline.info · Offensive & Active Directory
in Synacktiv Drops a Kerberos Reflection Bypass That Hands Attackers SYSTEM