CVE-2026-72980EPSS p45.5%

CVE-2026-72980CVE-2026-72980

microsoft / windows_10_1607

Description

Uncontrolled search path element in Windows Hello allows an authorized attacker to bypass a security feature locally.

Scoring

CVSS 4.4 ()
VectorCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS0.57% probability of exploitation · percentile 45.5% · 2026-10-05T12:00:23Z
Last modified2026-09-17
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.